Solaris 11 X86 Security Technical Implementation Guide
Pick two releases to diff their requirements.
Open a previous version of this STIG.
Digest of Updates +1 ⚠ 3 ✎ 18
Comparison against the immediately-prior release (V1R8). Rule matching uses the Group Vuln ID. Content-change detection compares the rule’s description, check, and fix text after stripping inline markup — cosmetic-only edits aren’t flagged.
Added rules 1
- V-72827 Medium Wireless network adapters must be disabled.
Severity changes 3
- V-47955 High Medium The operating system must have malicious code protection mechanisms at system entry and exit points to detect and eradicate malicious code transported by electronic mail, electronic mail attachments, web accesses, removable media, or other common means.
- V-47959 High Medium The operating system must employ malicious code protection mechanisms at workstations, servers, or mobile computing devices on the network to detect and eradicate malicious code transported by electronic mail, electronic mail attachments, web accesses, removable media, or other common means.
- V-47963 High Medium The operating system must prevent non-privileged users from circumventing malicious code protection capabilities.
Content changes 18
- V-47863 Medium checkfix The operating system must shut down by default upon audit failure (unless availability is an overriding concern).
- V-47895 Low check The limitpriv zone option must be set to the vendor default or less permissive.
- V-47915 High check The telnet service daemon must not be installed unless required.
- V-47943 Medium check User passwords must be changed at least every 56 days.
- V-48001 Low checkfix The system must require authentication before allowing modification of the boot devices or menus. Secure the GRUB Menu (Intel).
- V-48023 Low check Address Space Layout Randomization (ASLR) must be enabled.
- V-48025 Medium checkfix The system must implement non-executable program stacks.
- V-48037 Low check The operating system must have no files with extended attributes.
- V-48077 Medium check Reserved UIDs 0-99 must only be used by system accounts.
- V-48113 Medium checkfix Host-based authentication for login-based services must be disabled.
- V-48125 Medium check Unauthorized use of the at or cron capabilities must not be permitted.
- V-48187 Medium description The operating system must use mechanisms for authentication to a cryptographic module meeting the requirements of applicable federal laws, Executive orders, directives, policies, regulations, standards, and guidance for such authentication.
- V-48213 Low check The system must prevent local applications from generating source-routed packets.
- V-48243 Medium checkfix Systems must employ cryptographic hashes for passwords using the SHA-2 family of algorithms or FIPS 140-2 approved successors.
- V-59831 Medium descriptioncheckfix Run control scripts executable search paths must contain only authorized paths.
- V-59833 Medium descriptioncheckfix Run control scripts library search paths must contain only authorized paths.
- V-59835 Medium descriptioncheckfix Run control scripts lists of preloaded libraries must contain only authorized paths.
- V-59837 Medium check Run control scripts must not execute world writable programs or scripts.
- RMF Control
- AU-3
- Severity
- M
- CCI
- CCI-001487
- Version
- SOL-11.1-010040
- Vuln IDs
-
- V-47781
- Rule IDs
-
- SV-60657r1_rule
Checks: C-50237r1_chk
The Audit Configuration profile is required. This check applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this check applies. Check the status of the audit system. It must be auditing. # pfexec auditconfig -getcond If this command does not report: audit condition = auditing this is a finding.
Fix: F-51401r1_fix
The Audit Control profile is required. This action applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this action applies. If auditing has been disabled, it must be enabled with the following command: # pfexec audit -s
- RMF Control
- AU-7
- Severity
- M
- CCI
- CCI-000156
- Version
- SOL-11.1-010060
- Vuln IDs
-
- V-47783
- Rule IDs
-
- SV-60659r1_rule
Checks: C-50239r1_chk
The Audit Configuration profile is required. This check applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this check applies. Check the status of the audit system. It must be auditing. # pfexec auditconfig -getcond If this command does not report: audit condition = auditing this is a finding.
Fix: F-51403r1_fix
The Audit Control profile is required. This action applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this action applies. If auditing has been disabled, it must be enabled with the following command: # pfexec audit -s
- RMF Control
- AU-7
- Severity
- M
- CCI
- CCI-000157
- Version
- SOL-11.1-010070
- Vuln IDs
-
- V-47785
- Rule IDs
-
- SV-60661r1_rule
Checks: C-50241r2_chk
The Audit Configuration profile is required. This check applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this check applies. Check the status of the audit system. It must be auditing. # pfexec auditconfig -getcond If this command does not report: audit condition = auditing this is a finding.
Fix: F-51405r2_fix
The Audit Control profile is required. This action applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this action applies. If auditing has been disabled, it must be enabled with the following command: # pfexec audit -s
- RMF Control
- AU-7
- Severity
- M
- CCI
- CCI-000158
- Version
- SOL-11.1-010080
- Vuln IDs
-
- V-47787
- Rule IDs
-
- SV-60663r1_rule
Checks: C-50243r2_chk
The Audit Configuration profile is required. This check applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this check applies. Check the status of the audit system. It must be auditing. # pfexec auditconfig -getcond If this command does not report: audit condition = auditing this is a finding.
Fix: F-51407r2_fix
The Audit Control profile is required. This action applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this action applies. If auditing has been disabled, it must be enabled with the following command: # pfexec audit -s
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000169
- Version
- SOL-11.1-010100
- Vuln IDs
-
- V-47789
- Rule IDs
-
- SV-60665r1_rule
Checks: C-50245r2_chk
The Audit Configuration profile is required. This check applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this check applies. Check the status of the audit system. It must be auditing. # pfexec auditconfig -getcond If this command does not report: audit condition = auditing this is a finding.
Fix: F-51409r2_fix
The Audit Control profile is required. This action applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this action applies. If auditing has been disabled, it must be enabled with the following command: # pfexec audit -s
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- SOL-11.1-010120
- Vuln IDs
-
- V-47791
- Rule IDs
-
- SV-60667r1_rule
Checks: C-50247r1_chk
The Audit Configuration profile is required. This check applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this check applies. Check the status of the audit system. It must be auditing. # pfexec auditconfig -getcond If this command does not report: audit condition = auditing this is a finding.
Fix: F-51411r1_fix
The Audit Control profile is required. This action applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this action applies. If auditing has been disabled, it must be enabled with the following command: # pfexec audit -s
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000174
- Version
- SOL-11.1-010130
- Vuln IDs
-
- V-47793
- Rule IDs
-
- SV-60669r1_rule
Checks: C-50249r1_chk
The Audit Configuration profile is required. This check applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this check applies. Check the status of the audit system. It must be auditing. # pfexec auditconfig -getcond If this command does not report: audit condition = auditing this is a finding.
Fix: F-51413r1_fix
The Audit Control profile is required. This action applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this action applies. If auditing has been disabled, it must be enabled with the following command: # pfexec audit -s
- RMF Control
- AU-3
- Severity
- M
- CCI
- CCI-000130
- Version
- SOL-11.1-010140
- Vuln IDs
-
- V-47795
- Rule IDs
-
- SV-60671r1_rule
Checks: C-50251r1_chk
The Audit Configuration profile is required. This check applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this check applies. Check the status of the audit system. It must be auditing. # pfexec auditconfig -getcond If this command does not report: audit condition = auditing this is a finding.
Fix: F-51415r1_fix
The Audit Control profile is required. This action applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this action applies. If auditing has been disabled, it must be enabled with the following command: # pfexec audit -s
- RMF Control
- AU-3
- Severity
- M
- CCI
- CCI-000131
- Version
- SOL-11.1-010150
- Vuln IDs
-
- V-47797
- Rule IDs
-
- SV-60673r1_rule
Checks: C-50253r1_chk
The Audit Configuration profile is required. This check applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this check applies. Check the status of the audit system. It must be auditing. # pfexec auditconfig -getcond If this command does not report: audit condition = auditing this is a finding.
Fix: F-51417r1_fix
The Audit Control profile is required. This action applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this action applies. If auditing has been disabled, it must be enabled with the following command: # pfexec audit -s
- RMF Control
- AU-3
- Severity
- M
- CCI
- CCI-000132
- Version
- SOL-11.1-010160
- Vuln IDs
-
- V-47799
- Rule IDs
-
- SV-60675r1_rule
Checks: C-50255r1_chk
The Audit Configuration profile is required. This check applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this check applies. Check the status of the audit system. It must be auditing. # pfexec auditconfig -getcond If this command does not report: audit condition = auditing this is a finding.
Fix: F-51419r1_fix
The Audit Control profile is required. This action applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this action applies. If auditing has been disabled, it must be enabled with the following command: # pfexec audit -s
- RMF Control
- AU-3
- Severity
- M
- CCI
- CCI-000133
- Version
- SOL-11.1-010170
- Vuln IDs
-
- V-47801
- Rule IDs
-
- SV-60677r1_rule
Checks: C-50257r1_chk
The Audit Configuration profile is required. This check applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this check applies. Check the status of the audit system. It must be auditing. # pfexec auditconfig -getcond If this command does not report: audit condition = auditing this is a finding.
Fix: F-51421r1_fix
The Audit Control profile is required. This action applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this action applies. If auditing has been disabled, it must be enabled with the following command: # pfexec audit -s
- RMF Control
- AU-3
- Severity
- M
- CCI
- CCI-000134
- Version
- SOL-11.1-010180
- Vuln IDs
-
- V-47803
- Rule IDs
-
- SV-60679r1_rule
Checks: C-50259r1_chk
The Audit Configuration profile is required. This check applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this check applies. Check the status of the audit system. It must be auditing. # pfexec auditconfig -getcond If this command does not report: audit condition = auditing this is a finding.
Fix: F-51423r1_fix
The Audit Control profile is required. This action applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this action applies. If auditing has been disabled, it must be enabled with the following command: # pfexec audit -s
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SOL-11.1-010220
- Vuln IDs
-
- V-47805
- Rule IDs
-
- SV-60681r1_rule
Checks: C-50261r1_chk
The Audit Configuration profile is required. This check applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this check applies. Check that the flag for file deletions is enabled. # pfexec auditconfig -getflags | grep active |sed s/'active user default audit flags ='// | grep fd # pfexec auditconfig -getnaflags | grep active |sed s/'active user default audit flags ='// | grep fd If audit flags are not displayed, this is a finding. Determine if auditing policy is set to collect command line arguments. # pfexec auditconfig -getpolicy | grep active | grep argv If the active audit policies line does not appear, this is a finding.
Fix: F-51425r1_fix
The Audit Configuration profile is required. All audit flags must be enabled in a single command. This action applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this action applies. # pfexec auditconfig -setflags cusa,ps,fd,-fa,fm # pfexec auditconfig -setnaflags cusa,ps,fd,-fa,fm Enable the audit policy to collect command line arguments. # pfexec auditconfig -setpolicy +argv These changes will not affect users that are currently logged in.
- RMF Control
- AC-2
- Severity
- M
- CCI
- CCI-000018
- Version
- SOL-11.1-010230
- Vuln IDs
-
- V-47807
- Rule IDs
-
- SV-60683r1_rule
Checks: C-50263r1_chk
The Audit Configuration profile is required. This check applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this check applies. Check that the audit flag for process start is enabled. # pfexec auditconfig -getflags | grep active |sed s/'active user default audit flags ='// | grep ps # pfexec auditconfig -getnaflags | grep active |sed s/'active user default audit flags ='// | grep ps If audit flags are not displayed, this is a finding. Determine if auditing policy is set to collect command line arguments. # pfexec auditconfig -getpolicy | grep active | grep argv If the active audit policies line does not appear, this is a finding.
Fix: F-51427r1_fix
The Audit Configuration profile is required. All audit flags must be enabled in a single command. This action applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this action applies. # pfexec auditconfig -setflags cusa,ps,fd,-fa,fm # pfexec auditconfig -setnaflags cusa,ps,fd,-fa,fm Enable the audit policy to collect command line arguments. # pfexec auditconfig -setpolicy +argv These changes will not affect users that are currently logged in.
- RMF Control
- AC-2
- Severity
- M
- CCI
- CCI-001403
- Version
- SOL-11.1-010250
- Vuln IDs
-
- V-47809
- Rule IDs
-
- SV-60685r1_rule
Checks: C-50265r1_chk
The Audit Configuration profile is required. This check applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this check applies. # pfexec auditconfig -getflags | grep active |sed s/'active user default audit flags ='// | grep ps # pfexec auditconfig -getnaflags | grep active |sed s/'active user default audit flags ='// | grep ps If audit flags are not displayed, this is a finding. Determine if auditing policy is set to collect command line arguments. # pfexec auditconfig -getpolicy | grep active | grep argv If the active audit policies line does not appear, this is a finding.
Fix: F-51429r1_fix
The Audit Configuration profile is required. All audit flags must be enabled in a single command. This action applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this action applies. # pfexec auditconfig -setflags cusa,ps,fd,-fa,fm # pfexec auditconfig -setnaflags cusa,ps,fd,-fa,fm Enable the audit policy to collect command line arguments. # pfexec auditconfig -setpolicy +argv These changes will not affect users that are currently logged in.
- RMF Control
- AC-2
- Severity
- M
- CCI
- CCI-001404
- Version
- SOL-11.1-010260
- Vuln IDs
-
- V-47811
- Rule IDs
-
- SV-60687r1_rule
Checks: C-50267r1_chk
The Audit Configuration profile is required. Check that the audit flag for process start is enabled. This check applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this check applies. # pfexec auditconfig -getflags | grep active |sed s/'active user default audit flags ='// | grep ps # pfexec auditconfig -getnaflags | grep active |sed s/'active user default audit flags ='// | grep ps If audit flags are not displayed, this is a finding. Determine if auditing policy is set to collect command line arguments. # pfexec auditconfig -getpolicy | grep active | grep argv If the active audit policies line does not appear, this is a finding.
Fix: F-51431r1_fix
The Audit Configuration profile is required. All audit flags must be enabled in a single command. This action applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this action applies. # pfexec auditconfig -setflags cusa,ps,fd,-fa,fm # pfexec auditconfig -setnaflags cusa,ps,fd,-fa,fm Enable the audit policy to collect command line arguments. # pfexec auditconfig -setpolicy +argv These changes will not affect users that are currently logged in.
- RMF Control
- AC-2
- Severity
- M
- CCI
- CCI-001405
- Version
- SOL-11.1-010270
- Vuln IDs
-
- V-47813
- Rule IDs
-
- SV-60689r1_rule
Checks: C-50269r1_chk
The Audit Configuration profile is required. Check that the audit flag for process start is enabled. This check applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this check applies. # pfexec auditconfig -getflags | grep active |sed s/'active user default audit flags ='// | grep ps # pfexec auditconfig -getnaflags | grep active |sed s/'active user default audit flags ='// | grep ps If audit flags are not displayed, this is a finding. Determine if auditing policy is set to collect command line arguments. # pfexec auditconfig -getpolicy | grep active | grep argv If the active audit policies line does not appear, this is a finding.
Fix: F-51433r1_fix
The Audit Configuration profile is required. All audit flags must be enabled in a single command. This action applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this action applies. # pfexec auditconfig -setflags cusa,ps,fd,-fa,fm # pfexec auditconfig -setnaflags cusa,ps,fd,-fa,fm Enable the audit policy to collect command line arguments. # pfexec auditconfig -setpolicy +argv These changes will not affect users that are currently logged in.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-001589
- Version
- SOL-11.1-010290
- Vuln IDs
-
- V-47815
- Rule IDs
-
- SV-60691r1_rule
Checks: C-50271r1_chk
The Audit Configuration profile is required. This check applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this check applies. # pfexec auditconfig -getflags | grep active |sed s/'active user default audit flags ='// | grep as # pfexec auditconfig -getnaflags | grep active |sed s/'active user default audit flags ='// | grep as If audit flags are not displayed, this is a finding. Determine if auditing policy is set to collect command line arguments. # pfexec auditconfig -getpolicy | grep active | grep argv If the active audit policies line does not appear, this is a finding.
Fix: F-51435r1_fix
The Audit Configuration profile is required. All audit flags must be enabled in a single command. This action applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this action applies. # pfexec auditconfig -setflags cusa,ps,fd,-fa,fm # pfexec auditconfig -setnaflags cusa,ps,fd,-fa,fm Enable the audit policy to collect command line arguments. # pfexec auditconfig -setpolicy +argv These changes will not affect users that are currently logged in.
- RMF Control
- AC-6
- Severity
- M
- CCI
- CCI-000040
- Version
- SOL-11.1-010300
- Vuln IDs
-
- V-47817
- Rule IDs
-
- SV-60693r1_rule
Checks: C-50273r1_chk
The Audit Configuration profile is required. This check applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this check applies. # pfexec auditconfig -getflags | grep active |sed s/'active user default audit flags ='// | grep as # pfexec auditconfig -getnaflags | grep active |sed s/'active user default audit flags ='// | grep as If audit flags are not displayed, this is a finding. Determine if auditing policy is set to collect command line arguments. # pfexec auditconfig -getpolicy | grep active | grep argv If the active audit policies line does not appear, this is a finding.
Fix: F-51437r1_fix
The Audit Configuration profile is required. All audit flags must be enabled in a single command. This action applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this action applies. # pfexec auditconfig -setflags cusa,ps,fd,-fa,fm # pfexec auditconfig -setnaflags cusa,ps,fd,-fa,fm Enable the audit policy to collect command line arguments. # pfexec auditconfig -setpolicy +argv These changes will not affect users that are currently logged in.
- RMF Control
- AC-17
- Severity
- L
- CCI
- CCI-000067
- Version
- SOL-11.1-010310
- Vuln IDs
-
- V-47819
- Rule IDs
-
- SV-60695r1_rule
Checks: C-50275r1_chk
The Audit Configuration profile is required. Check that the audit flag for auditing login and logout is enabled. This check applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this check applies. # pfexec auditconfig -getflags | grep active |sed s/'active user default audit flags ='// | grep lo # pfexec auditconfig -getnaflags | grep active |sed s/'active user default audit flags ='// | grep lo If audit flags are not displayed, this is a finding. Determine if auditing policy is set to collect command line arguments. # pfexec auditconfig -getpolicy | grep active | grep argv If the active audit policies line does not appear, this is a finding.
Fix: F-51439r1_fix
The Audit Configuration profile is required. All audit flags must be enabled in a single command. This action applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this action applies. # pfexec auditconfig -setflags cusa,ps,fd,-fa,fm # pfexec auditconfig -setnaflags cusa,ps,fd,-fa,fm Enable the audit policy to collect command line arguments. # pfexec auditconfig -setpolicy +argv These changes will not affect users that are currently logged in.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-001589
- Version
- SOL-11.1-010320
- Vuln IDs
-
- V-47821
- Rule IDs
-
- SV-60697r1_rule
Checks: C-50277r1_chk
The Audit Configuration profile is required. Check that the audit flag for auditing file access is enabled. This check applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this check applies. # pfexec auditconfig -getflags | grep active |sed s/'active user default audit flags ='// | grep fm # pfexec auditconfig -getnaflags | grep active |sed s/'active user default audit flags ='// | grep fm If audit flags are not displayed, this is a finding. Determine if auditing policy is set to collect command line arguments. # pfexec auditconfig -getpolicy | grep active | grep argv If the active audit policies line does not appear, this is a finding.
Fix: F-51441r1_fix
The Audit Configuration profile is required. All audit flags must be enabled in a single command. This action applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this action applies. # pfexec auditconfig -setflags cusa,ps,fd,-fa,fm # pfexec auditconfig -setnaflags cusa,ps,fd,-fa,fm Enable the audit policy to collect command line arguments. # pfexec auditconfig -setpolicy +argv These changes will not affect users that are currently logged in.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-001589
- Version
- SOL-11.1-010330
- Vuln IDs
-
- V-47823
- Rule IDs
-
- SV-60699r1_rule
Checks: C-50279r1_chk
The Audit Configuration profile is required. This check applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this check applies. Check that the audit flag for auditing administrative actions is enabled. # pfexec auditconfig -getflags | grep active |sed s/'active user default audit flags ='// | grep as # pfexec auditconfig -getnaflags | grep active |sed s/'active user default audit flags ='// | grep as If audit flags are not displayed, this is a finding. Determine if auditing policy is set to collect command line arguments. # pfexec auditconfig -getpolicy | grep active | grep argv If the active audit policies line does not appear, this is a finding.
Fix: F-51443r1_fix
The Audit Configuration profile is required. All audit flags must be enabled in a single command. This action applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this action applies. # pfexec auditconfig -setflags cusa,ps,fd,-fa,fm # pfexec auditconfig -setnaflags cusa,ps,fd,-fa,fm Enable the audit policy to collect command line arguments. # pfexec auditconfig -setpolicy +argv These changes will not affect users that are currently logged in.
- RMF Control
- CM-6
- Severity
- L
- CCI
- CCI-000366
- Version
- SOL-11.1-010340
- Vuln IDs
-
- V-47825
- Rule IDs
-
- SV-60701r1_rule
Checks: C-50281r1_chk
The Audit Configuration profile is required. Check that the audit flag for auditing file access is enabled. This check applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this check applies. # pfexec auditconfig -getflags | grep active |sed s/'active user default audit flags ='// | grep fa # pfexec auditconfig -getnaflags | grep active |sed s/'active user default audit flags ='// | grep fa If audit flags are not displayed, this is a finding. Determine if auditing policy is set to collect command line arguments. # pfexec auditconfig -getpolicy | grep active | grep argv If the active audit policies line does not appear, this is a finding.
Fix: F-51445r1_fix
The Audit Configuration profile is required. All audit flags must be enabled in a single command. This action applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this action applies. # pfexec auditconfig -setflags cusa,ps,fd,-fa,fm # pfexec auditconfig -setnaflags cusa,ps,fd,-fa,fm Enable the audit policy to collect command line arguments. # pfexec auditconfig -setpolicy +argv These changes will not affect users that are currently logged in.
- RMF Control
- AU-10
- Severity
- L
- CCI
- CCI-000166
- Version
- SOL-11.1-010350
- Vuln IDs
-
- V-47827
- Rule IDs
-
- SV-60703r2_rule
Checks: C-50283r1_chk
Audit Configuration rights profile is required. This check applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this check applies. Check that the syslog audit plugin is enabled. # pfexec auditconfig -getplugin | grep audit_syslog If "inactive" appears, this is a finding. Determine which system-log service instance is online. # pfexec svcs system-log Check that the /etc/syslog.conf or /etc/rsyslog.conf file is configured properly: # grep audit.notice /etc/syslog.conf or # grep audit.notice /etc/rsyslog.conf If audit.notice @remotesystemname points to an invalid remote system, this is a finding. If no output is produced, this is a finding. Check the remote syslog host to ensure that audit records can be found for this host.
Fix: F-51447r3_fix
Service Management, Audit Configuration and Audit Control rights profile is required. This action applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this action applies. Configure Solaris 11 to use the syslog audit plugin # pfexec auditconfig -setplugin audit_syslog active Determine which system-log service instance is online. # pfexec svcs system-log If the default system-log service is online: # pfedit /etc/syslog.conf Add the line: audit.notice @[remotesystemname] Replacing the remote system name with the correct hostname. If the rsyslog service is online, modify the /etc/rsyslog.conf file. # pfedit /etc/rsyslog.conf Add the line: audit.notice @[remotesystemname] Replacing the remote system name with the correct hostname. Create the log file on the remote system # touch /var/adm/auditlog Refresh the syslog service # pfexec svcadm refresh system/system-log:default or # pfexec svcadm refresh system/system-log:rsyslog Refresh the audit service # pfexec audit -s
- RMF Control
- CM-6
- Severity
- L
- CCI
- CCI-000366
- Version
- SOL-11.1-010360
- Vuln IDs
-
- V-47831
- Rule IDs
-
- SV-60705r1_rule
Checks: C-50285r1_chk
This check applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this check applies. For each user on the system (not including root), check to see if special auditing flag configurations are set. # userattr audit_flags [username] If any flags are returned, this is a finding.
Fix: F-51449r1_fix
The root role is required. This action applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this action applies. For each user on the system, remove all special audit configuration flags. # usermod -K audit_flags= [username]
- RMF Control
- AU-5
- Severity
- M
- CCI
- CCI-000143
- Version
- SOL-11.1-010370
- Vuln IDs
-
- V-47835
- Rule IDs
-
- SV-60709r1_rule
Checks: C-50289r1_chk
This check applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this check applies. The root role is required. Verify the presence of an audit_warn entry in /etc/mail/aliases. # /usr/lib/sendmail -bv audit_warn If the response is: audit_warn... User unknown this is a finding. Review the output of the command and verify that the audit_warn alias notifies the appropriate users in this form: audit_warn:user1,user2 If an appropriate user is not listed, this is a finding.
Fix: F-51453r1_fix
The root role is required. This action applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this action applies. Add an audit_warn alias to /etc/mail/aliases that will forward to designated system administrator(s). # pfedit /etc/mail/aliases Insert a line in the form: audit_warn:user1,user2 Put the updated aliases file into service. # newaliases
- RMF Control
- CM-6
- Severity
- L
- CCI
- CCI-000366
- Version
- SOL-11.1-100050
- Vuln IDs
-
- V-47837
- Rule IDs
-
- SV-60711r1_rule
Checks: C-50293r1_chk
This check applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this check applies. List the non-global zones on the system. # zoneadm list -vi | grep -v global The Audit Configuration profile is required. Determine whether the "perzone" auditing policy is in effect. # pfexec auditconfig -getpolicy | grep active | grep perzone If output is returned, this is a finding.
Fix: F-51455r1_fix
This check applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this check applies. List the non-global zones on the system. # zoneadm list -vi | grep -v global The Audit Configuration profile is required. Disable the "perzone" auditing policy. # pfexec auditconfig -setpolicy -perzone
- RMF Control
- CM-6
- Severity
- L
- CCI
- CCI-000366
- Version
- SOL-11.1-100040
- Vuln IDs
-
- V-47839
- Rule IDs
-
- SV-60713r1_rule
Checks: C-50295r1_chk
This check applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this check applies. List the non-global zones on the system. # zoneadm list -vi | grep -v global The Audit Configuration profile is required. Determine whether the "zonename" auditing policy is in effect. # pfexec auditconfig -getpolicy | grep active | grep zonename If no output is returned, this is a finding.
Fix: F-51457r1_fix
This check applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this check applies. List the non-global zones on the system. # zoneadm list -vi | grep -v global The Audit Configuration profile is required. Enable the "zonename" auditing policy. # pfexec auditconfig -setpolicy +zonename
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SOL-11.1-100030
- Vuln IDs
-
- V-47841
- Rule IDs
-
- SV-60715r1_rule
Checks: C-50297r1_chk
This check applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this check applies. List the non-global zones on the system. # zoneadm list -vi | grep -v global List the configuration for each zone. # zonecfg -z [zonename] info | grep dev Check for device lines. If such a line exists and is not approved by security, this is a finding.
Fix: F-51459r1_fix
This check applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this check applies. The Zone Security profile is required: Remove all device assignments from the non-global zone. # pfexec zonecfg -z [zone] delete device [device]
- RMF Control
- AU-5
- Severity
- H
- CCI
- CCI-000144
- Version
- SOL-11.1-010380
- Vuln IDs
-
- V-47843
- Rule IDs
-
- SV-60717r1_rule
Checks: C-50299r1_chk
This check applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this check applies. The root role is required. Verify the presence of an audit_warn entry in /etc/mail/aliases. # /usr/lib/sendmail -bv audit_warn If the response is: audit_warn... User unknown this is a finding. Review the output of the command and verify that the audit_warn alias notifies the appropriate users in this form: audit_warn:user1,user2 If an appropriate user is not listed, this is a finding.
Fix: F-51461r1_fix
The root role is required. This action applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this action applies. Add an audit_warn alias to /etc/mail/aliases that will forward to designated system administrator(s). # pfedit /etc/mail/aliases Insert a line in the form: audit_warn:user1,user2 Put the updated aliases file into service. # newaliases
- RMF Control
- AU-5
- Severity
- H
- CCI
- CCI-000139
- Version
- SOL-11.1-010390
- Vuln IDs
-
- V-47845
- Rule IDs
-
- SV-60719r1_rule
Checks: C-50301r1_chk
This check applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this check applies. The root role is required. Verify the presence of an audit_warn entry in /etc/mail/aliases. # /usr/lib/sendmail -bv audit_warn If the response is: audit_warn... User unknown this is a finding. Review the output of the command and verify that the audit_warn alias notifies the appropriate users in this form: audit_warn:user1,user2 If an appropriate user is not listed, this is a finding.
Fix: F-51463r1_fix
The root role is required. This action applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this action applies. Add an audit_warn alias to /etc/mail/aliases that will forward to designated system administrator(s). # pfedit /etc/mail/aliases Insert a line in the form: audit_warn:user1,user2 Put the updated aliases file into service. # newaliases
- RMF Control
- AU-4
- Severity
- M
- CCI
- CCI-000137
- Version
- SOL-11.1-010400
- Vuln IDs
-
- V-47857
- Rule IDs
-
- SV-60731r2_rule
Checks: C-50305r2_chk
The Audit Configuration profile is required. This check applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this check applies. Review the current audit file space limitations # pfexec auditconfig -getplugin audit_binfile Plugin: audit_binfile (active) The output of the command will appear in this form. Attributes: p_dir=/var/audit;p_fsize=4M;p_minfree=2 If p_minfree is not equal to "2" of greater, this is a finding. p_dir defines the current audit file system. Note: By default in Solaris 11.1, /var/audit is a link to /var/share/audit which is mounted on rpool/VARSHARE. Check that zfs compression is enabled for the audit file system. # zfs get compression [poolname/filesystemname] If compression is off, this is a finding. Check that a ZFS quota is enforced for the audit filesystem. # zfs get quota [poolname/filesystemname] If quota is set to "none", this is a finding. Ensure that a reservation of space is enforced on /var/share so that other users do not use up audit space. # zfs get quota,reservation [poolname/filesystemname] If reservation is set to "none", this is a finding.
Fix: F-51473r1_fix
The Audit Configuration, Audit Control and ZFS File System Management profiles are required. This action applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this action applies. Determine the audit system directory name: # pfexec auditconfig -getplugin audit_binfile Plugin: audit_binfile (active) The output of the command will appear in this form: Attributes: p_dir=/var/audit;p_fsize=4M;p_minfree=1; p_dir defines the current audit file system. Note: By default in Solaris 11.1, /var/audit is a link to /var/share/audit which is mounted on rpool/VARSHARE. Set a minimum percentage of free space on the audit_binfile plugin to 2%. # pfexec auditconfig -setplugin audit_binfile p_minfree=2 Restart the audit system. # pfexec audit -s Enable compression for the audit filesystem. # pfexec zfs set compression=on [poolname/filesystemname] Set a ZFS quota on the default /var/share filesystem for audit records to ensure that the root pool is not filled up with audit logs. # pfexec zfs set quota=XXG [poolname/filesystemname] This commands sets the quota to XX Gigabytes. This value should be based upon organizational requirements. Set a ZFS reservation on the default /var/share filesystem for audit records to ensure that the audit file system is guaranteed a fixed amount of storage. # pfexec zfs set reservation=XXG [poolname/filesystemname] This commands sets the quota to XX Gigabytes. This value should be based upon organizational requirements.
- RMF Control
- AU-5
- Severity
- M
- CCI
- CCI-000140
- Version
- SOL-11.1-010420
- Vuln IDs
-
- V-47863
- Rule IDs
-
- SV-60737r2_rule
Checks: C-50309r2_chk
The Audit Configuration profile is required. This check applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this check applies. # pfexec auditconfig -getpolicy | grep ahlt If the output does not include "ahlt" as an active audit policy, this is a finding. # pfexec auditconfig -getpolicy | grep active | grep cnt If the output includes "cnt" as an active audit policy, this is a finding.
Fix: F-51481r3_fix
The Audit Configuration profile is required. This action applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this action applies. Set audit policy to halt and suspend on failure. # pfexec auditconfig -setpolicy +ahlt # pfexec auditconfig -setpolicy -cnt
- RMF Control
- AU-9
- Severity
- M
- CCI
- CCI-000162
- Version
- SOL-11.1-010440
- Vuln IDs
-
- V-47869
- Rule IDs
-
- SV-60741r1_rule
Checks: C-50311r1_chk
The root role is required. This check applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this check applies. Check that the directory storing the audit files is owned by root and has permissions 640 or less. Note: By default in Solaris 11.1, /var/audit is a link to /var/share/audit which is mounted on rpool/VARSHARE. Determine the location of the audit trail files # pfexec auditconfig -getplugin audit_binfile The output will appear in this form: Plugin: audit_binfile (active) Attributes: p_dir=/var/audit;p_fsize=0;p_minfree=1 The p_dir attribute defines the location of the audit directory. # ls -ld /var/share/audit Check the audit directory is owned by root, group is root, and permissions are 640 (rw- r-- ---) or less. If the permissions are excessive, this is a finding.
Fix: F-51485r1_fix
Note: By default in Solaris 11.1, /var/audit is a link to /var/share/audit which is mounted on rpool/VARSHARE. The root role is required. This action applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this action applies. Determine the location of the audit trail files # pfexec auditconfig -getplugin audit_binfile| The output will appear in this form: Plugin: audit_binfile (active) Attributes: p_dir=/var/audit;p_fsize=0;p_minfree=1 The p_dir attribute defines the location of the audit directory. # chown root [directory] # chgrp root [directory] # chmod 640 [directory]
- RMF Control
- AU-9
- Severity
- H
- CCI
- CCI-000163
- Version
- SOL-11.1-010450
- Vuln IDs
-
- V-47875
- Rule IDs
-
- SV-60747r1_rule
Checks: C-50313r1_chk
The root role is required. This check applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this check applies. Check that the directory storing the audit files is owned by root and has permissions 640 or less. Note: By default in Solaris 11.1, /var/audit is a link to /var/share/audit which is mounted on rpool/VARSHARE. Determine the location of the audit trail files # pfexec auditconfig -getplugin audit_binfile The output will appear in this form: Plugin: audit_binfile (active) Attributes: p_dir=/var/audit;p_fsize=0;p_minfree=1 The p_dir attribute defines the location of the audit directory. # ls -ld /var/share/audit Check the audit directory is owned by root, group is root, and permissions are 640 (rw- r-- ---) or less. If the permissions are excessive, this is a finding.
Fix: F-51489r1_fix
Note: By default in Solaris 11.1, /var/audit is a link to /var/share/audit which is mounted on rpool/VARSHARE. The root role is required. This action applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this action applies. Determine the location of the audit trail files # pfexec auditconfig -getplugin audit_binfile| The output will appear in this form: Plugin: audit_binfile (active) Attributes: p_dir=/var/audit;p_fsize=0;p_minfree=1 The p_dir attribute defines the location of the audit directory. # chown root [directory] # chgrp root [directory] # chmod 640 [directory]
- RMF Control
- AU-9
- Severity
- H
- CCI
- CCI-000164
- Version
- SOL-11.1-010460
- Vuln IDs
-
- V-47879
- Rule IDs
-
- SV-60751r1_rule
Checks: C-50315r2_chk
The root role is required. This check applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this check applies. Check that the directory storing the audit files is owned by root and has permissions 640 or less. Note: By default in Solaris 11.1, /var/audit is a link to /var/share/audit which is mounted on rpool/VARSHARE. Determine the location of the audit trail files # pfexec auditconfig -getplugin audit_binfile The output will appear in this form: Plugin: audit_binfile (active) Attributes: p_dir=/var/audit;p_fsize=0;p_minfree=1 The p_dir attribute defines the location of the audit directory. # ls -ld /var/share/audit Check the audit directory is owned by root, group is root, and permissions are 640 (rw- r-- ---) or less. If the permissions are excessive, this is a finding.
Fix: F-51491r2_fix
Note: By default in Solaris 11.1, /var/audit is a link to /var/share/audit which is mounted on rpool/VARSHARE. The root role is required. This action applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this action applies. Determine the location of the audit trail files # pfexec auditconfig -getplugin audit_binfile| The output will appear in this form: Plugin: audit_binfile (active) Attributes: p_dir=/var/audit;p_fsize=0;p_minfree=1 The p_dir attribute defines the location of the audit directory. # chown root [directory] # chgrp root [directory] # chmod 640 [directory]
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SOL-11.1-020010
- Vuln IDs
-
- V-47881
- Rule IDs
-
- SV-60753r2_rule
Checks: C-50317r1_chk
The Software Installation Profile is required. An up-to-date Solaris repository must be accessible to the system. Enter the command: # pkg publisher to determine the current repository publisher. If a repository is not accessible, it may need to be locally installed and configured. Check for Solaris software package updates: # pfexec pkg update -n If the command does not report "No updates available for this image," this is a finding.
Fix: F-51493r1_fix
The Software Installation Profile is required. An up-to-date Solaris repository must be accessible to the system. Enter the command: # pkg publisher to determine the current repository publisher. If a repository is not accessible, it may need to be locally installed and configured. Update system packages to the current version. # pfexec pkg update A reboot may be required for the updates to take effect.
- RMF Control
- CM-5
- Severity
- M
- CCI
- CCI-000352
- Version
- SOL-11.1-020020
- Vuln IDs
-
- V-47883
- Rule IDs
-
- SV-60755r1_rule
Checks: C-50319r1_chk
Determine what the signature policy is for pkg publishers: # pkg property | grep signature-policy Check that output produces: signature-policy verify If the output does not confirm that signature-policy verify is active, this is a finding.
Fix: F-51495r1_fix
The Software Installation Profile is required. Configure the package system to ensure that digital signatures are verified. # pfexec pkg set-property signature-policy verify
- RMF Control
- AU-9
- Severity
- M
- CCI
- CCI-001493
- Version
- SOL-11.1-020030
- Vuln IDs
-
- V-47885
- Rule IDs
-
- SV-60757r1_rule
Checks: C-50321r1_chk
The Software Installation Profile is required. Determine what the signature policy is for pkg publishers: # pkg property | grep signature-policy Check that output produces: signature-policy verify If the output does not confirm that signature-policy verify is active, this is a finding. Check that package permissions are configured and signed per vendor requirements. # pkg verify If the command produces any output unrelated to STIG changes, this is a finding. There is currently a Solaris 11 bug 16267888 which reports pkg verify errors for a variety of python packages. These can be ignored.
Fix: F-51497r1_fix
The Software Installation Profile is required. Configure the package system to ensure that digital signatures are verified. # pfexec pkg set-property signature-policy verify Check that package permissions are configured per vendor requirements. # pfexec pkg verify If any errors are reported unrelated to STIG changes, use: # pfexec pkg fix to bring configuration settings and permissions into factory compliance.
- RMF Control
- AU-9
- Severity
- M
- CCI
- CCI-001494
- Version
- SOL-11.1-020040
- Vuln IDs
-
- V-47887
- Rule IDs
-
- SV-60759r1_rule
Checks: C-50323r1_chk
The Software Installation Profile is required. Determine what the signature policy is for pkg publishers: # pkg property | grep signature-policy Check that output produces: signature-policy verify If the output does not confirm that signature-policy verify is active, this is a finding. Check that package permissions are configured and signed per vendor requirements. # pkg verify If the command produces any output unrelated to STIG changes, this is a finding. There is currently a Solaris 11 bug 16267888 which reports pkg verify errors for a variety of python packages. These can be ignored.
Fix: F-51499r1_fix
The Software Installation Profile is required. Configure the package system to ensure that digital signatures are verified. # pfexec pkg set-property signature-policy verify Check that package permissions are configured per vendor requirements. # pfexec pkg verify If any errors are reported unrelated to STIG changes, use: # pfexec pkg fix to bring configuration settings and permissions into factory compliance.
- RMF Control
- AU-9
- Severity
- M
- CCI
- CCI-001495
- Version
- SOL-11.1-020050
- Vuln IDs
-
- V-47889
- Rule IDs
-
- SV-60761r1_rule
Checks: C-50325r1_chk
The Software Installation Profile is required. Determine what the signature policy is for pkg publishers: # pkg property | grep signature-policy Check that output produces: signature-policy verify If the output does not confirm that signature-policy verify is active, this is a finding. Check that package permissions are configured and signed per vendor requirements. # pkg verify If the command produces any output unrelated to STIG changes, this is a finding. There is currently a Solaris 11 bug 16267888 which reports pkg verify errors for a variety of python packages. These can be ignored.
Fix: F-51501r1_fix
The Software Installation Profile is required. Configure the package system to ensure that digital signatures are verified. # pfexec pkg set-property signature-policy verify Check that package permissions are configured per vendor requirements. # pfexec pkg verify If any errors are reported unrelated to STIG changes, use: # pfexec pkg fix to bring configuration settings and permissions into factory compliance.
- RMF Control
- AU-9
- Severity
- M
- CCI
- CCI-001496
- Version
- SOL-11.1-020080
- Vuln IDs
-
- V-47891
- Rule IDs
-
- SV-60763r1_rule
Checks: C-50327r1_chk
The Software Installation Profile is required. Determine what the signature policy is for pkg publishers: # pkg property | grep signature-policy Check that output produces: signature-policy verify If the output does not confirm that signature-policy verify is active, this is a finding. Check that package permissions are configured and signed per vendor requirements. # pkg verify If the command produces any output unrelated to STIG changes, this is a finding. There is currently a Solaris 11 bug 16267888 which reports pkg verify errors for a variety of python packages. These can be ignored.
Fix: F-51503r1_fix
The Software Installation Profile is required. Configure the package system to ensure that digital signatures are verified. # pfexec pkg set-property signature-policy verify Check that package permissions are configured per vendor requirements. # pfexec pkg verify If any errors are reported unrelated to STIG changes, use: # pfexec pkg fix to bring configuration settings and permissions into factory compliance.
- RMF Control
- CM-6
- Severity
- L
- CCI
- CCI-000366
- Version
- SOL-11.1-020090
- Vuln IDs
-
- V-47893
- Rule IDs
-
- SV-60765r1_rule
Checks: C-50329r1_chk
Determine if the finger package is installed. # pkg list service/network/finger If an installed package named service/network/finger is listed, this is a finding.
Fix: F-51505r1_fix
The Software Installation Profile is required. # pfexec pkg uninstall service/network/finger
- RMF Control
- CM-6
- Severity
- L
- CCI
- CCI-000366
- Version
- SOL-11.1-100020
- Vuln IDs
-
- V-47895
- Rule IDs
-
- SV-60767r3_rule
Checks: C-50331r3_chk
This check applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this check applies. List the non-global zones on the system. # zoneadm list -vi | grep -v global From the output list of non-global zones found, determine if any are Kernel zones. # zoneadm list -cv | grep [zonename] | grep solaris-kz Exclude any Kernel zones found from the list of local zones. List the configuration for each zone. # zonecfg -z [zonename] info |grep limitpriv If the output of this command has a setting for limitpriv and it is not: limitpriv: default this is a finding.
Fix: F-51507r1_fix
This check applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this check applies. The Zone Security profile is required: Change the "limitpriv" setting to default. # pfexec zonecfg -z [zone] set limitpriv=default
- RMF Control
- CM-6
- Severity
- L
- CCI
- CCI-000366
- Version
- SOL-11.1-100010
- Vuln IDs
-
- V-47897
- Rule IDs
-
- SV-60769r1_rule
Checks: C-50333r1_chk
This check applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this check applies. Check the ownership of the files and directories. # pkg verify system/zones The command should return no output. If output is produced, this is a finding.
Fix: F-51509r3_fix
This check applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this check applies. The Software Installation profile is required. Change the ownership and permissions of the files and directories to the factory default. # pkg fix system/zones
- RMF Control
- SC-5
- Severity
- M
- CCI
- CCI-001095
- Version
- SOL-11.1-090280
- Vuln IDs
-
- V-47899
- Rule IDs
-
- SV-60771r1_rule
Checks: C-50335r1_chk
Ask the operator if Solaris 11 resource controls are configured limiting user memory, process table slots, network bandwidth, and threads utilization If resource controls are not implemented to limit user memory usage, process table slots, network bandwidth, and/or threads utilization, this is a finding.
Fix: F-51511r1_fix
Use Solaris 11 projects and resource controls to limit the amount of memory and CPU resources available to users and applications.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SOL-11.1-020100
- Vuln IDs
-
- V-47901
- Rule IDs
-
- SV-60773r1_rule
Checks: C-50337r1_chk
Determine if the legacy remote access package is installed. # pkg list service/network/legacy-remote-utilities If an installed package named service/network/legacy-remote-utilities is listed, this is a finding.
Fix: F-51513r1_fix
The Software Installation Profile is required. # pfexec pkg uninstall service/network/legacy-remote-utilities
- RMF Control
- SI-11
- Severity
- M
- CCI
- CCI-001311
- Version
- SOL-11.1-090270
- Vuln IDs
-
- V-47903
- Rule IDs
-
- SV-60775r1_rule
Checks: C-50339r2_chk
Ask the operator if DoD-approved SCAP compliance checking software is installed and run on a periodic basis. If DoD-approved SCAP compliance checking software is not installed and/or not run on a periodic basis, this is a finding.
Fix: F-51515r1_fix
Install, configure, and run DoD-approved SCAP compliance checking software on a periodic basis. Review the output of the software and document any out-of-compliance issues.
- RMF Control
- CM-6
- Severity
- H
- CCI
- CCI-000366
- Version
- SOL-11.1-020110
- Vuln IDs
-
- V-47905
- Rule IDs
-
- SV-60777r1_rule
Checks: C-50341r1_chk
Determine if the NIS package is installed. # pkg list service/network/nis If an installed package named "service/network/nis" is listed, this is a finding.
Fix: F-51517r1_fix
The Software Installation Profile is required. # pfexec pkg uninstall service/network/nis
- RMF Control
- SI-6
- Severity
- M
- CCI
- CCI-001291
- Version
- SOL-11.1-090250
- Vuln IDs
-
- V-47907
- Rule IDs
-
- SV-60779r1_rule
Checks: C-50343r1_chk
Ask the operator if DoD-approved SCAP compliance checking software is installed and run on a periodic basis. If DoD-approved SCAP compliance checking software is not installed and/or not run on a periodic basis, this is a finding.
Fix: F-51519r1_fix
Install, configure, and run DoD-approved SCAP compliance checking software on a periodic basis. Review the output of the software and document any out-of-compliance issues.
- RMF Control
- CM-6
- Severity
- L
- CCI
- CCI-000366
- Version
- SOL-11.1-020120
- Vuln IDs
-
- V-47909
- Rule IDs
-
- SV-60781r1_rule
Checks: C-50345r1_chk
Determine if the pidgin package is installed. # pkg list communication/im/pidgin If an installed package named communication/im/pidgin is listed, this is a finding.
Fix: F-51521r1_fix
The Software Installation Profile is required. # pfexec pkg uninstall communication/im/pidgin
- RMF Control
- CM-6
- Severity
- H
- CCI
- CCI-000366
- Version
- SOL-11.1-020130
- Vuln IDs
-
- V-47911
- Rule IDs
-
- SV-60783r1_rule
Checks: C-50347r1_chk
Determine if the FTP package is installed. # pkg list service/network/ftp If an installed package named "service/network/ftp" is listed and not required for operations, this is a finding.
Fix: F-51523r1_fix
The Software Installation Profile is required. # pfexec pkg uninstall service/network/ftp
- RMF Control
- CM-6
- Severity
- H
- CCI
- CCI-000366
- Version
- SOL-11.1-020140
- Vuln IDs
-
- V-47913
- Rule IDs
-
- SV-60785r2_rule
Checks: C-50349r2_chk
Determine if the TFTP package is installed. # pkg list service/network/tftp If an installed package named "/service/network/tftp" is listed and not required for operations, this is a finding.
Fix: F-51525r2_fix
The Software Installation Profile is required. # pfexec pkg uninstall install/installadm # pfexec pkg uninstall service/network/tftp
- RMF Control
- CM-6
- Severity
- H
- CCI
- CCI-000366
- Version
- SOL-11.1-020150
- Vuln IDs
-
- V-47915
- Rule IDs
-
- SV-60787r2_rule
Checks: C-50351r2_chk
Determine if the telnet daemon package in installed. # pkg list service/network/telnet If an installed package named "service/network/telnet" is listed and vntsd is not in use for LDoms, this is a finding.
Fix: F-51527r1_fix
The Software Installation Profile is required. # pfexec pkg uninstall service/network/telnet
- RMF Control
- CM-6
- Severity
- L
- CCI
- CCI-000366
- Version
- SOL-11.1-020160
- Vuln IDs
-
- V-47917
- Rule IDs
-
- SV-60789r2_rule
Checks: C-50353r2_chk
Determine if the UUCP package is installed. # pkg list /service/network/uucp If an installed package named "/service/network/uucp" is listed, this is a finding.
Fix: F-51529r3_fix
The Software Installation Profile is required. # pfexec pkg uninstall /service/network/uucp
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SOL-11.1-020170
- Vuln IDs
-
- V-47919
- Rule IDs
-
- SV-60791r1_rule
Checks: C-50355r1_chk
Check the status of the rpcbind service local_only property. # svcprop -p config/local_only network/rpc/bind If the state is not "true", this is a finding.
Fix: F-51531r1_fix
The Service Management profile is required. Configure the rpc/bind service for local only access. #svccfg -s network/rpc/bind setprop config/local_only=true
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SOL-11.1-020180
- Vuln IDs
-
- V-47921
- Rule IDs
-
- SV-60793r1_rule
Checks: C-50357r1_chk
Determine if the VNC server package is installed. # pkg list x11/server/xvnc If an installed package named "x11/server/xvnc is listed" is listed, this is a finding.
Fix: F-51533r1_fix
The Software Installation Profile is required. # pfexec pkg uninstall x11/server/xvnc
- RMF Control
- CM-8
- Severity
- M
- CCI
- CCI-000416
- Version
- SOL-11.1-020190
- Vuln IDs
-
- V-47923
- Rule IDs
-
- SV-60795r1_rule
Checks: C-50359r1_chk
The Software Installation Profile is required. Display the installation history of packages on the system to ensure that no undesirable packages have been installed: # pkg history -o finish,user,operation,command |grep install If the install command is listed as "/usr/bin/packagemanager", execute the command: # pkg history -l to determine which packages were installed during package manager sessions. If undocumented or unapproved packages have been installed, this is a finding.
Fix: F-51535r1_fix
The Software Installation Profile is required. Review and report any unauthorized package installation operations. If necessary, remove unauthorized packages. # pfexec pkg uninstall [package name]
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- SOL-11.1-020220
- Vuln IDs
-
- V-47925
- Rule IDs
-
- SV-60797r1_rule
Checks: C-50361r1_chk
Identify the packages installed on the system. # pkg list Any unauthorized software packages listed in the output are a finding.
Fix: F-51537r1_fix
The Software Installation profile is required. Identify packages installed on the system: # pkg list uninstall unauthorized packages: # pfexec pkg uninstall [ package name]
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000386
- Version
- SOL-11.1-020230
- Vuln IDs
-
- V-47927
- Rule IDs
-
- SV-60799r1_rule
Checks: C-50363r1_chk
Identify the packages installed on the system. # pkg list Any unauthorized software packages listed in the output are a finding.
Fix: F-51539r1_fix
The Software Installation profile is required. Identify packages installed on the system: # pkg list uninstall unauthorized packages: # pfexec pkg uninstall [ package name]
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SOL-11.1-030010
- Vuln IDs
-
- V-47929
- Rule IDs
-
- SV-60801r1_rule
Checks: C-50365r1_chk
Determine if the X11 server system is providing remote services on the network. # svcprop -p options/tcp_listen svc:/application/x11/x11-server If the output of the command is "true" and network access to graphical user login is not required, this is a finding.
Fix: F-51541r1_fix
The System Administrator profile is required: Configure the X11 server for local system only graphics access. # pfexec svccfg -s svc:/application/x11/x11-server setprop options/tcp_listen=false
- RMF Control
- CM-6
- Severity
- L
- CCI
- CCI-000366
- Version
- SOL-11.1-030030
- Vuln IDs
-
- V-47931
- Rule IDs
-
- SV-60803r1_rule
Checks: C-50367r1_chk
Determine the status of the Generic Security Services. # svcs -Ho state svc:/network/rpc/gss If the GSS service is reported as online, this is a finding.
Fix: F-51543r1_fix
The Service Management profile is required: Disable the GSS service. # pfexec svcadm disable svc:/network/rpc/gss
- RMF Control
- CM-6
- Severity
- L
- CCI
- CCI-000366
- Version
- SOL-11.1-030040
- Vuln IDs
-
- V-47933
- Rule IDs
-
- SV-60805r1_rule
Checks: C-50369r1_chk
Determine all of the systems services that are enabled on the system. # svcs -a | grep online Document all enabled services and disable any that are not required.
Fix: F-51545r1_fix
The Service Management profile is required: Disable any other service not required. # pfexec svcadm disable [service name]
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SOL-11.1-030050
- Vuln IDs
-
- V-47935
- Rule IDs
-
- SV-60807r1_rule
Checks: C-50371r1_chk
Check that TCP Wrappers are enabled and the host.deny and host.allow files exist. # inetadm -p | grep tcp_wrappers If the output of this command is "tcp_wrappers=FALSE", this is a finding. # ls /etc/hosts.deny /etc/hosts.deny # ls /etc/hosts.allow /etc/hosts.allow If these files do not exist or do not contain the names of allowed or denied hosts, this is a finding.
Fix: F-51547r2_fix
The root role is required. To enable TCP Wrappers, run the following commands: 1. Create and customize your policy in /etc/hosts.allow: # echo "ALL: [net]/[mask], [net]/[mask], ..." > /etc/hosts.allow where each [net>/[mask> combination (for example, the Class C address block "192.168.1.0/255.255.255.0") can represent one network block in use by your organization that requires access to this system. 2. Create a default deny policy in /etc/hosts.deny: # echo "ALL: ALL" >/etc/hosts.deny 3. Enable TCP Wrappers for all services started by inetd: # inetadm -M tcp_wrappers=TRUE The versions of SSH and sendmail that ship with Solaris 11 will automatically use TCP Wrappers to filter access if a hosts.allow or hosts.deny file exists.
- RMF Control
- CM-6
- Severity
- L
- CCI
- CCI-000366
- Version
- SOL-11.1-090240
- Vuln IDs
-
- V-47937
- Rule IDs
-
- SV-60809r1_rule
Checks: C-50373r1_chk
Ask the operators if they use vi, emacs, or gedit to make changes to system files. If vi, emacs, or gedit are used to make changes to system files, this is a finding.
Fix: F-51549r1_fix
Advise the operators to use pdfedit or other appropriate command line tools to make system changes instead of vi, emacs, or gedit. Oracle Solaris includes administrative configuration files which use pfedit, and the solaris.admin.edit/path_to_file authorization is not recommended. Alternate commands exist which are both domain-specific and safer. For example, for the /etc/passwd, /etc/shadow, or /etc/user_attr files, use instead passwd, useradd, userdel, or usermod. For the /etc/group file, use instead groupadd, groupdel, or groupmod. For updating /etc/security/auth_attr, /etc/security/exec_attr, or /etc/security/prof_attr, the preferred command is profiles.
- RMF Control
- AC-19
- Severity
- M
- CCI
- CCI-000087
- Version
- SOL-11.1-030060
- Vuln IDs
-
- V-47939
- Rule IDs
-
- SV-60811r1_rule
Checks: C-50375r1_chk
This check applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this check applies. Determine if the removable media volume manager is running. # svcs -Ho state svc:/system/filesystem/rmvolmgr:default If the output reports that the service is "online", this is a finding.
Fix: F-51551r1_fix
The Service Management profile is required. This action applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this action applies. Disable the rmvolmgr service. # pfexec svcadm disable svc:/system/filesystem/rmvolmgr:default
- RMF Control
- AU-9
- Severity
- M
- CCI
- CCI-001348
- Version
- SOL-11.1-090220
- Vuln IDs
-
- V-47941
- Rule IDs
-
- SV-60813r1_rule
Checks: C-50377r1_chk
This check applies to the global zone only. Determine the zone that you a currently securing. # zonename If the command output is "global" this check applies. The operator must back up audit records at least every 7 days. If the operator is unable to provide a documented procedure or the documented procedure is not being followed, then this is a finding.
Fix: F-51553r1_fix
This fix applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this check applies. The operator shall back up audit records at least every seven days.
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-000199
- Version
- SOL-11.1-040010
- Vuln IDs
-
- V-47943
- Rule IDs
-
- SV-60815r2_rule
Checks: C-50379r3_chk
The root role is required. Determine if user passwords are properly configured to be changed every 56 days. # logins -ox |awk -F: '( $1 != "root" && $8 != "LK" && $8 != "NL" && $11 != "56" ) { print }' If output is returned and the listed account is accessed via direct logon, this is a finding. Check that /etc/default/password is configured to enforce password expiration every 56 days or less. # grep "^MAXWEEKS=" /etc/default/passwd If the command does not report MAXWEEKS=8 or less, this is a finding.
Fix: F-51555r1_fix
The User Security role is required. Change each username to enforce 56 day password changes. # pfexec passwd -x 56 [username] # pfedit /etc/default/passwd Search for MAXWEEKS. Change the line to read: MAXWEEKS=8
- RMF Control
- SI-4
- Severity
- L
- CCI
- CCI-001274
- Version
- SOL-11.1-090200
- Vuln IDs
-
- V-47945
- Rule IDs
-
- SV-60817r1_rule
Checks: C-50381r1_chk
The operator will ensure that DoD approved intrusion detection software is installed, operating, and updated monthly. The configurations will be updated regularly. The software will be maintained per vendor documentation. If the operator is unable to provide a documented configuration for an installed intrusion detection system or if the intrusion detection system is not properly configured, maintained or used, this is a finding.
Fix: F-51557r1_fix
The operator will ensure that DoD approved intrusion detection software is installed, operating, and updated monthly. The configurations will be updated regularly. The software will be maintained per vendor documentation.
- RMF Control
- SI-4
- Severity
- L
- CCI
- CCI-001269
- Version
- SOL-11.1-090180
- Vuln IDs
-
- V-47947
- Rule IDs
-
- SV-60819r1_rule
Checks: C-50383r1_chk
The operator will ensure that DoD approved intrusion detection software is installed, operating, and updated monthly. The configurations will be updated regularly. The software will be maintained per vendor documentation. If the operator is unable to provide a documented configuration for an installed intrusion detection system or if the intrusion detection system is not properly configured, maintained or used, this is a finding.
Fix: F-51559r1_fix
The operator will ensure that DoD approved intrusion detection software is installed, operating, and updated monthly. The configurations will be updated regularly. The software will be maintained per vendor documentation.
- RMF Control
- AC-2
- Severity
- L
- CCI
- CCI-000016
- Version
- SOL-11.1-040020
- Vuln IDs
-
- V-47949
- Rule IDs
-
- SV-60821r1_rule
Checks: C-50385r1_chk
The root role is required. Determine if an expiration date is set for temporary accounts. # logins -aox |awk -F: '($14 == "0") {print}' This command produces a list of accounts with no expiration date set. If any of these accounts are temporary accounts, this is a finding. # logins -aox |awk -F: '($14 != "0") {print}' This command produces a list of accounts with an expiration date set as defined in the last field. If any accounts have a date that is not within 72 hours, this is a finding.
Fix: F-51561r1_fix
The User Security role is required. Apply an expiration date to temporary users. # pfexec usermod -e "[date]" [username] Enter the date in the form mm/dd/yyyy such that it is within 72 hours.
- RMF Control
- SI-4
- Severity
- L
- CCI
- CCI-001265
- Version
- SOL-11.1-090170
- Vuln IDs
-
- V-47951
- Rule IDs
-
- SV-60823r1_rule
Checks: C-50387r1_chk
The operator will ensure that DoD approved intrusion detection software is installed, operating, and updated monthly. The configurations will be updated regularly. The software will be maintained per vendor documentation. If the operator is unable to provide a documented configuration for an installed intrusion detection system or if the intrusion detection system is not properly configured, maintained or used, this is a finding.
Fix: F-51563r1_fix
The operator will ensure that DoD approved intrusion detection software is installed, operating, and updated monthly. The configurations will be updated regularly. The software will be maintained per vendor documentation.
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-000198
- Version
- SOL-11.1-040030
- Vuln IDs
-
- V-47953
- Rule IDs
-
- SV-60825r2_rule
Checks: C-50389r3_chk
The root role is required. Check whether the minimum time period between password changes for each user account is 1 day or greater. # awk -F: '$4 < 1 {print $1}' /etc/shadow If any results are returned that are not associated with a system account, this is a finding. Check that /etc/default/password is configured to minimum password change time of 1 week. # grep "^MINWEEKS=" /etc/default/passwd If the command does not report MINWEEKS=1, this is a finding.
Fix: F-51565r1_fix
The root role is required. # pfedit /etc/default/passwd file. Locate the line containing: MINWEEKS Change the line to read: MINWEEKS=1 Set the per-user minimum password change times by using the following command on each user account. # passwd -n [number of days] [accountname]
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001239
- Version
- SOL-11.1-090140
- Vuln IDs
-
- V-47955
- Rule IDs
-
- SV-60827r3_rule
Checks: C-50391r3_chk
The operator will ensure that anti-virus software is installed and operating. If the operator is unable to provide a documented configuration for an installed anti-virus software system or if not properly used, this is a finding.
Fix: F-51567r3_fix
The operator will ensure that anti-virus software is installed and operating.
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-000205
- Version
- SOL-11.1-040040
- Vuln IDs
-
- V-47957
- Rule IDs
-
- SV-60829r1_rule
Checks: C-50393r1_chk
Check the system password length setting. # grep ^PASSLENGTH /etc/default/passwd If PASSLENGTH is not set to 15 or more, this is a finding.
Fix: F-51569r1_fix
The root role is required. # pfedit /etc/default/passwd Locate the line containing: PASSLENGTH Change the line to read PASSLENGTH=15
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001668
- Version
- SOL-11.1-090130
- Vuln IDs
-
- V-47959
- Rule IDs
-
- SV-60831r3_rule
Checks: C-50395r3_chk
The operator will ensure that anti-virus software is installed and operating. If the operator is unable to provide a documented configuration for an installed anti-virus software system or if not properly used, this is a finding.
Fix: F-51571r3_fix
The operator will ensure that anti-virus software is installed and operating.
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-000200
- Version
- SOL-11.1-040050
- Vuln IDs
-
- V-47961
- Rule IDs
-
- SV-60833r1_rule
Checks: C-50397r1_chk
Determine if the password history setting is configured properly. # grep ^HISTORY /etc/default/passwd If HISTORY is commented out or is not set to 5 or more, this is a finding.
Fix: F-51573r1_fix
The root role is required. # pfedit /etc/default/passwd Locate the line containing: HISTORY Change the line to read: HISTORY=5
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001248
- Version
- SOL-11.1-090120
- Vuln IDs
-
- V-47963
- Rule IDs
-
- SV-60835r3_rule
Checks: C-50399r3_chk
The operator will ensure that anti-virus software is installed and operating. If the operator is unable to provide a documented configuration for an installed anti-virus software system or if not properly used, this is a finding.
Fix: F-51575r3_fix
The operator will ensure that anti-virus software is installed and operating.
- RMF Control
- SI-2
- Severity
- M
- CCI
- CCI-001233
- Version
- SOL-11.1-090110
- Vuln IDs
-
- V-47965
- Rule IDs
-
- SV-60837r1_rule
Checks: C-50401r2_chk
The operator will ensure that a DoD approved HBSS is installed, configured, and properly operating. Ask the operator to document the HBSS software installation and configuration. If the operator is not able to provide a documented configuration for an installed HBSS or if the HBSS is not properly configured, maintained, or used, this is a finding.
Fix: F-51577r1_fix
The operator will ensure that a DoD approved HBSS software is installed and operating continuously.
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-000195
- Version
- SOL-11.1-040060
- Vuln IDs
-
- V-47967
- Rule IDs
-
- SV-60839r2_rule
Checks: C-50403r1_chk
Check /etc/default/passwd to verify the MINDIFF setting. # grep ^MINDIFF /etc/default/passwd If the setting is not present, or is less than 8, this is a finding.
Fix: F-51579r1_fix
The root role is required. # pfedit /etc/default/passwd Search for MINDIFF. Change the line to read: MINDIFF=8
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-001695
- Version
- SOL-11.1-090100
- Vuln IDs
-
- V-47969
- Rule IDs
-
- SV-60841r1_rule
Checks: C-50405r2_chk
The Firefox browser is included with Solaris. Ensure that Java and JavaScript access by Firefox are disabled. Start Firefox. Access the Edit > Preferences menu item. Access the Content tab. If Enable JavaScript is checked, this is a finding. Access the Tools > Add ons menu item Choose the Plugins tab. If Java is enabled, this is a finding.
Fix: F-51581r2_fix
Start Firefox. Access the Edit > Preferences menu item. Choose the Content tab. Disable JavaScript using the check box. Access the Tools > Add ons menu item. Choose the Plugins tab. Disable Java by clicking on the Disable button.
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-000192
- Version
- SOL-11.1-040070
- Vuln IDs
-
- V-47971
- Rule IDs
-
- SV-60843r1_rule
Checks: C-50407r1_chk
Check the MINUPPER setting. # grep ^MINUPPER /etc/default/passwd If MINUPPER is not set to 1 or more, this is a finding.
Fix: F-51583r1_fix
The root role is required. # pfedit /etc/default/passwd Locate the line containing: MINUPPER Change the line to read: MINUPPER=1
- RMF Control
- CP-9
- Severity
- M
- CCI
- CCI-000539
- Version
- SOL-11.1-090070
- Vuln IDs
-
- V-47973
- Rule IDs
-
- SV-60845r1_rule
Checks: C-50409r1_chk
The operations staff shall ensure that proper backups are created, tested, and archived. Ask the operator for documentation on the backup procedures implemented. If the backup procedures are not documented then this is a finding.
Fix: F-51585r1_fix
The operations staff shall install, configure, test, and verify operating system backup software. Additionally, all backup procedures must be documented.
- RMF Control
- CP-9
- Severity
- M
- CCI
- CCI-000537
- Version
- SOL-11.1-090060
- Vuln IDs
-
- V-47975
- Rule IDs
-
- SV-60847r1_rule
Checks: C-50411r1_chk
The operations staff shall ensure that proper backups are created, tested, and archived. Ask the operator for documentation on the backup procedures implemented. If the backup procedures are not documented then this is a finding.
Fix: F-51587r1_fix
The operations staff shall install, configure, test, and verify operating system backup software. Additionally, all backup procedures must be documented.
- RMF Control
- CP-9
- Severity
- M
- CCI
- CCI-000535
- Version
- SOL-11.1-090050
- Vuln IDs
-
- V-47977
- Rule IDs
-
- SV-60849r1_rule
Checks: C-50413r1_chk
The operations staff shall ensure that proper backups are created, tested, and archived. Ask the operator for documentation on the backup procedures implemented. If the backup procedures are not documented then this is a finding.
Fix: F-51589r1_fix
The operations staff shall install, configure, test, and verify operating system backup software. Additionally, all backup procedures must be documented.
- RMF Control
- CM-6
- Severity
- L
- CCI
- CCI-000366
- Version
- SOL-11.1-090040
- Vuln IDs
-
- V-47979
- Rule IDs
-
- SV-60851r1_rule
Checks: C-50415r1_chk
Check the system for unnecessary user accounts. # getent passwd Some examples of unnecessary accounts include games, news, gopher, ftp, and lp. If any unnecessary accounts are found, this is a finding.
Fix: F-51591r1_fix
The root role is required. Remove all unnecessary accounts, such as games, from the /etc/passwd file before connecting a system to the network. Other accounts, such as news and gopher, associated with a service not in use should also be removed. Identify unnecessary accounts. # getent passwd Remove unnecessary accounts. # userdel [username]
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-000193
- Version
- SOL-11.1-040080
- Vuln IDs
-
- V-47981
- Rule IDs
-
- SV-60853r1_rule
Checks: C-50417r1_chk
Check the MINLOWER setting. # grep ^MINLOWER /etc/default/passwd If MINLOWER is not set to 1 or more, this is a finding.
Fix: F-51593r1_fix
The root role is required. # pfedit /etc/default/passwd Locate the line containing: MINLOWER Change the line to read: MINLOWER=1
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SOL-11.1-090030
- Vuln IDs
-
- V-47983
- Rule IDs
-
- SV-60855r2_rule
Checks: C-50419r2_chk
The Audit Review profile is required. This check applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this check applies. Use the "auditreduce" command to check for multiple accesses to an account # auditreduce -c lo -u [shared_user_name] | praudit -l If users log directly into accounts, rather than using the "su" command from their own named account to access them, this is a finding. Also, ask the SA or the IAO if shared accounts are logged into directly or if users log into an individual account and switch user to the shared account.
Fix: F-51595r2_fix
The root role is required. This action applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this action applies. Use the switch user ("su") command from a named account login to access shared accounts. Maintain audit trails that identify the actual user of the account name. Document requirements and procedures for users/administrators to log into their own accounts first and then switch user ("su") to the shared account.
- RMF Control
- AU-8
- Severity
- M
- CCI
- CCI-000160
- Version
- SOL-11.1-090020
- Vuln IDs
-
- V-47985
- Rule IDs
-
- SV-60857r2_rule
Checks: C-50421r4_chk
NTP must be used and used only in the global zone. Determine the zone that you are currently securing. # zonename If the command output is not "global", then NTP must be disabled. Check the system for a running NTP daemon. # svcs -Ho state ntp If NTP is online, this is a finding. If the output from "zonename" is "global", then NTP must be enabled. Check the system for a running NTP daemon. # svcs -Ho state ntp If NTP is not online, this is a finding. If NTP is running, confirm the servers and peers or multicast client (as applicable) are local or an authoritative U.S. DoD source. For the NTP daemon # more /etc/inet/ntp.conf If a non-local/non-authoritative (non-U.S. DoD source, non-USNO-based, or non-GPS) time server is used, this is a finding. Determine if the time synchronization frequency is correct. # grep "maxpoll" /etc/inet/ntp.conf If the command returns "File not found" or any value for maxpoll, this is a finding. Determine if the running NTP server is configured properly. # ntpq -p | awk '($6 ~ /[0-9]+/ && $6 > 86400) { print $1" "$6 }' This will print out the name of any time server whose current polling time is greater than 24 hours (along with the actual value). If there is any output, this is a finding.
Fix: F-51597r2_fix
The root role is required. Determine the zone that you are currently securing. # zonename If the command output is not "global", then NTP must be disabled. # svcadm disable ntp If the output from "zonename" is "global", then NTP must be enabled. To activate the ntpd daemon, the ntp.conf file must first be created. # cp /etc/inet/ntp.client /etc/inet/ntp.conf # pfedit /etc/inet/ntp.conf Make site-specific changes to this file as needed in the form. server [ntpserver] Locate the line containing maxpoll (if it exists). Delete the line. Start the ntpd daemon. # svcadm enable ntp Use a local authoritative time server synchronizing to an authorized DoD time source, a USNO-based time server, or a GPS. Ensure all systems in the facility feed from one or more local time servers that feed from the authoritative time server. Edit the NTP configuration files and make the necessary changes to add the approved time servers per Solaris documentation.
- RMF Control
- SI-7
- Severity
- M
- CCI
- CCI-001297
- Version
- SOL-11.1-090010
- Vuln IDs
-
- V-47987
- Rule IDs
-
- SV-60859r1_rule
Checks: C-50423r2_chk
The root role is required. Solaris 11 includes the Basic Account and Reporting Tool (BART) which uses cryptographic-strength checksums and file system metadata to determine changes. By default, the manifest generator catalogs all attributes of all files in the root (/) file system. File systems mounted on the root file system are cataloged only if they are of the same type as the root file system. A Baseline BART manifest may exist in: /var/adm/log/bartlogs/[control manifest filename] If a BART manifest does not exist, this is a finding. At least weekly, create a new BART baseline report. # bart create > /var/adm/log/bartlogs/[new manifest filename] Compare the new report to the previous report to identify any changes in the system baseline. # bart compare /var/adm/log/bartlogs/[baseline manifest filename> /var/adm/log/bartlogs/[new manifest filename] Examine the BART report for changes. If there are changes to system files in /etc that are not approved, this is a finding.
Fix: F-51599r2_fix
The root role is required. Solaris 11 includes the Basic Account and Reporting Tool (BART) which uses cryptographic-strength checksums and file system metadata to determine changes. By default, the manifest generator catalogs all attributes of all files in the root (/) file system. File systems mounted on the root file system are cataloged only if they are of the same type as the root file system. Create a protected area to store BART manifests. # mkdir /var/adm/log/bartlogs # chmod 700 /var/adm/log/bartlogs After initial installation and configuration of the system, create a manifest report of the current baseline. # bart create > /var/adm/log/bartlogs/[baseline manifest filename]
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-000194
- Version
- SOL-11.1-040090
- Vuln IDs
-
- V-47989
- Rule IDs
-
- SV-60861r1_rule
Checks: C-50425r1_chk
Check the MINDIGIT setting. # grep ^MINDIGIT /etc/default/passwd If the MINDIGIT setting is less than 1, this is a finding.
Fix: F-51601r1_fix
The root role is required. # pfedit /etc/default/passwd Locate the line containing: MINDIGIT Change the line to read: MINDIGIT=1
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-001619
- Version
- SOL-11.1-040100
- Vuln IDs
-
- V-47991
- Rule IDs
-
- SV-60863r1_rule
Checks: C-50427r1_chk
Check the MINSPECIAL setting. # grep ^MINSPECIAL /etc/default/passwd If the MINSPECIAL setting is less than 1, this is a finding.
Fix: F-51603r1_fix
The root role is required. # pfedit /etc/default/passwd a Locate the line containing: MINSPECIAL Change the line to read: MINSPECIAL=1
- RMF Control
- CM-6
- Severity
- L
- CCI
- CCI-000366
- Version
- SOL-11.1-040110
- Vuln IDs
-
- V-47993
- Rule IDs
-
- SV-60865r1_rule
Checks: C-50429r1_chk
Check the MAXREPEATS setting. # grep ^MAXREPEATS /etc/default/passwd If the MAXREPEATS setting is greater than 3, this is a finding.
Fix: F-51605r1_fix
The root role is required. # pfedit /etc/default/passwd Locate the line containing: MAXREPEATS Change the line to read: MAXREPEATS=3
- RMF Control
- CM-6
- Severity
- H
- CCI
- CCI-000366
- Version
- SOL-11.1-080160
- Vuln IDs
-
- V-47995
- Rule IDs
-
- SV-60867r1_rule
Checks: C-50431r1_chk
The root role is required. Check the SNMP configuration for default passwords. Locate and examine the SNMP configuration. Procedure: Find any occurrences of the snmpd.conf file delivered with Solaris packages: # pkg search -Ho path snmpd.conf | awk '{ print "/"$1 }' # more [filename] Identify any community names or user password configurations. If any community name or password is set to a default value, such as public, private, snmp-trap, password, or any value which does not meet DISA password requirements, this is a finding.
Fix: F-51607r1_fix
The root role is required. Change the default snmpd.conf community passwords. To change them, locate the snmpd.conf file and edit it. # pfedit [filename] Locate the line system-group-read-community which has a default password of public and make the password something more random (less guessable). Make the same changes for the lines that read system- group-write-community, read-community, write-community, trap, and trap-community. Read the information in the file carefully. The trap is defining who to send traps to, for instance, by default. It is not a password, but the name of a host.
- RMF Control
- CP-10
- Severity
- M
- CCI
- CCI-000553
- Version
- SOL-11.1-080150
- Vuln IDs
-
- V-47997
- Rule IDs
-
- SV-60869r1_rule
Checks: C-50433r1_chk
Solaris 11 ZFS copy-on-write model allows filesystem accesses to work according to a transactional model, such that on-disk content is always consistent and cannot be configured to be out of compliance. Determine if any UFS file systems are mounted with the "nologging" option. # mount|grep nologging If any file systems are listed, this is a finding.
Fix: F-51609r1_fix
The root role is required. Solaris 11 ZFS copy-on-write model allows filesystem accesses to work according to a transactional model, such that on-disk content is always consistent and cannot be configured to be out of compliance. If any UFS file systems are mounted with the "nologging" options, remove that option from the /etc/vfstab file. # pfedit /etc/vfstab Locate any file systems listed with the "nologging" option and delete the keyword "nologging".
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SOL-11.1-040120
- Vuln IDs
-
- V-47999
- Rule IDs
-
- SV-60871r1_rule
Checks: C-50435r1_chk
The root role is required. Determine if accounts with blank or null passwords exist. # logins -po If any account is listed, this is a finding.
Fix: F-51611r1_fix
The root role is required. Remove, lock, or configure a password for any account with a blank password. # passwd [username] or Use the passwd -l command to lock accounts that are not permitted to execute commands. or Use the passwd -N command to set accounts to be non-login.
- RMF Control
- CM-6
- Severity
- L
- CCI
- CCI-000366
- Version
- SOL-11.1-080140
- Vuln IDs
-
- V-48001
- Rule IDs
-
- SV-60873r3_rule
Checks: C-50437r2_chk
This check applies to X86 systems only. This check applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this check applies. # grep source /rpool/boot/grub/grub.cfg source custom.cfg If the output does not contain "source custom.cfg" on a line of its own, this is a finding. # grep superusers /rpool/boot/grub/custom.cfg. # grep password_pbkdf2 /rpool/boot/grub/custom.cfg If no superuser name and password are defined, this is a finding.
Fix: F-51613r2_fix
The root role is required. This action applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this action applies. Update GRUB to use a custom configuration file. # pfedit /rpool/boot/grub/grub.cfg Insert the line: source custom.cfg Create a password hash. # /usr/lib/grub2/bios/bin/grub-mkpasswd-pbkdf2 Enter password: Reenter password: Your PBKDF2 is ....... Copy the long password hash in its entirety. # pfedit /rpool/boot/grub/custom.cfg Insert the lines: set superusers="[username]" password_pbkdf2 [username] [password hash] Restart the system.
- RMF Control
- CM-6
- Severity
- L
- CCI
- CCI-000366
- Version
- SOL-11.1-080120
- Vuln IDs
-
- V-48005
- Rule IDs
-
- SV-60877r2_rule
Checks: C-50441r1_chk
This check applies to X86 compatible platforms. On systems with a BIOS or system controller, verify a supervisor or administrator password is set. If a password is not set, this is a finding. If the BIOS or system controller supports user-level access in addition to supervisor/administrator access, determine if this access is enabled. If so, this is a finding.
Fix: F-51617r1_fix
Consult the hardware vendor's documentation to determine how to start the system and access the BIOS controls. Access the system's BIOS or system controller. Set a supervisor/administrator password if one has not been set. Disable a user-level password if one has been set.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SOL-11.1-080110
- Vuln IDs
-
- V-48007
- Rule IDs
-
- SV-60879r1_rule
Checks: C-50443r1_chk
The root role is required. This check applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this check applies. Determine the location of the system dump directory. # dumpadm | grep directory Check the permissions of the kernel core dump data directory. # ls -ld [savecore directory] If the directory has a mode more permissive than 0700 (rwx --- ---), this is a finding.
Fix: F-51619r1_fix
The root role is required. This action applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this action applies. Determine the location of the system dump directory. # dumpadm | grep directory Change the group-owner of the kernel core dump data directory. # chmod 0700 [savecore directory]
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SOL-11.1-080100
- Vuln IDs
-
- V-48009
- Rule IDs
-
- SV-60881r1_rule
Checks: C-50445r1_chk
The root role is required. This check applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this check applies. Determine the location of the system dump directory. # dumpadm | grep directory Check ownership of the core dump data directory. # ls -l [savecore directory] If the directory is not group-owned by root, this is a finding. In Solaris 11, /var/crash is linked to /var/share/crash.
Fix: F-51621r2_fix
The root role is required. This action applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this action applies. Determine the location of the system dump directory. # dumpadm | grep directory Change the group-owner of the kernel core dump data directory. # chgrp root [kernel core dump data directory] In Solaris 11, /var/crash is linked to /var/share/crash.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SOL-11.1-080090
- Vuln IDs
-
- V-48011
- Rule IDs
-
- SV-60883r1_rule
Checks: C-50447r1_chk
The root role is required. This check applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this check applies. Determine the location of the system dump directory. # dumpadm | grep directory Check the ownership of the kernel core dump data directory. # ls -ld [savecore directory] If the kernel core dump data directory is not owned by root, this is a finding. In Solaris 11, /var/crash is linked to /var/share/crash.
Fix: F-51623r1_fix
The root role is required. This action applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this action applies. Determine the location of the system dump directory. # dumpadm | grep directory Change the owner of the kernel core dump data directory to root. # chown root [savecore directory] In Solaris 11, /var/crash is linked to /var/share/crash.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SOL-11.1-080080
- Vuln IDs
-
- V-48013
- Rule IDs
-
- SV-60885r1_rule
Checks: C-50449r1_chk
The root role is required. This check applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this check applies. Verify savecore is not used. # dumpadm | grep 'Savecore enabled' If the value is yes, this is a finding.
Fix: F-51625r1_fix
The root role is required. This action applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this action applies. Disable savecore. # dumpadm -n
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SOL-11.1-080070
- Vuln IDs
-
- V-48015
- Rule IDs
-
- SV-60887r1_rule
Checks: C-50451r1_chk
Check the defined directory for process core dumps. # coreadm | grep "global core file pattern" Check the permissions of the directory. # ls -lLd [core file directory] If the directory has a mode more permissive than 0700 (rwx --- ---), this is a finding.
Fix: F-51627r1_fix
The root role is required. Change the mode of the core file directory. # chmod 0700 [core file directory]
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SOL-11.1-080060
- Vuln IDs
-
- V-48017
- Rule IDs
-
- SV-60889r1_rule
Checks: C-50453r1_chk
Check the defined directory for process core dumps. # coreadm | grep "global core file pattern" Check the group ownership of the directory. # ls -lLd [core file directory] If the directory is not group-owned by root, this is a finding.
Fix: F-51629r1_fix
The root role is required. Change the group-owner of the core file directory. # chgrp root [core file directory]
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SOL-11.1-080050
- Vuln IDs
-
- V-48019
- Rule IDs
-
- SV-60891r1_rule
Checks: C-50455r1_chk
Check the defined directory for process core dumps. # coreadm | grep "global core file pattern" Check the ownership of the directory. # ls -lLd [core file directory] If the directory is not owned by root, this is a finding.
Fix: F-51631r1_fix
The root role is required. Change the owner of the core file directory. # chown root [core file directory]
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SOL-11.1-080040
- Vuln IDs
-
- V-48021
- Rule IDs
-
- SV-60893r2_rule
Checks: C-50457r2_chk
Check the process core dump configuration. # coreadm | grep enabled If any lines are returned by coreadm other than "logging", this is a finding.
Fix: F-51633r2_fix
The Maintenance and Repair profile is required. Change the process core dump configuration to disable core dumps globally and on a per process basis. # coreadm -d global # coreadm -d process # coreadm -d global-setid # coreadm -d proc-setid # coreadm -e log
- RMF Control
- CM-6
- Severity
- L
- CCI
- CCI-000366
- Version
- SOL-11.1-080030
- Vuln IDs
-
- V-48023
- Rule IDs
-
- SV-60895r2_rule
Checks: C-50459r2_chk
This check applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this check applies. Determine if address space layout randomization is enabled. # sxadm info -p | grep aslr | grep enabled If no output is produced, this is a finding.
Fix: F-51635r1_fix
The root role is required. This action applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this action applies. Enable address space layout randomization. # sxadm delcust aslr Enabling ASLR may affect the function or stability of some applications, including those that use Solaris Intimate Shared Memory features.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SOL-11.1-080020
- Vuln IDs
-
- V-48025
- Rule IDs
-
- SV-60897r2_rule
Checks: C-50461r2_chk
Determine the OS version you are currently securing. # uname –v If the OS version is 11.3 or newer, this check applies to all zones and relies on the "sxadm" command. Determine if the system implements non-executable program stacks. # sxadm status -p nxstack | cut -d: -f2 enabled (all) If the command output is not "enabled (all)", this is a finding. For Solaris 11, 11.1, and 11.2, this check applies to the global zone only and the "/etc/system" file is inspected. Determine the zone that you are currently securing. # zonename If the command output is "global", determine if the system implements non-executable program stacks. # grep noexec_user_stack /etc/system If the noexec_user_stack is not set to 1, this is a finding.
Fix: F-51637r2_fix
The root role is required. Determine the OS version you are currently securing. # uname –v If the OS version is 11.3 or newer, enable non-executable program stacks using the "sxadm" command. # pfexec sxadm enable nxstack For Solaris 11, 11.1, and 11.2, this action applies to the global zone only and the "/etc/system" file is updated. Determine the zone that you are currently securing. # zonename If the command output is "global", modify the "/etc/system" file. # pfedit /etc/system add the line: set noexec_user_stack=1 Solaris 11, 11.1, and 11.2 systems will need to be restarted for the setting to take effect.
- RMF Control
- CM-6
- Severity
- H
- CCI
- CCI-000366
- Version
- SOL-11.1-080010
- Vuln IDs
-
- V-48027
- Rule IDs
-
- SV-60899r1_rule
Checks: C-50463r1_chk
Determine the operating system version. # uname -a If the release is not supported by the vendor, this is a finding.
Fix: F-51639r1_fix
Upgrade to a supported version of the operating system.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SOL-11.1-070260
- Vuln IDs
-
- V-48029
- Rule IDs
-
- SV-60901r1_rule
Checks: C-50465r1_chk
The root role is required. Identify all file system objects that have non-standard access control lists enabled. # find / \( -fstype nfs -o -fstype cachefs -o -fstype autofs \ -o -fstype ctfs -o -fstype mntfs -o -fstype objfs \ -o -fstype proc \) -prune -o -acl -ls This command should return no output. If output is created, this is a finding. If the files are approved to have ACLs by organizational security policy, document the files and the reason that ACLs are required.
Fix: F-51641r1_fix
The root role is required. Remove ACLs that are not approved in the security policy. For ZFS file systems, remove all extended ACLs with the following command: # chmod A- [filename] For UFS file systems Determine the ACLs that are set on a file: # getfacl [filename] Remove any ACL configurations that are set: # setfacl -d [ACL] [filename]
- RMF Control
- AU-9
- Severity
- M
- CCI
- CCI-001352
- Version
- SOL-11.1-070250
- Vuln IDs
-
- V-48031
- Rule IDs
-
- SV-60903r2_rule
Checks: C-50467r2_chk
The audit configuration profile is required. This check applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this check applies. Determine the location of the local audit trail files. # auditconfig -getplugin audit_binfile Plugin: audit_binfile (active) Attributes: p_dir=/var/audit;p_fsize=4M;p_minfree=1;" In this example, the audit files can be found in /var/audit. Check that the permissions on the audit files are 640 (rw- r-- --) or less permissive. # ls -al /var/audit # ls -l /var/audit/* If the permissions are more permissive than 640, this is a finding. Note: The default Solaris 11 location for /var/audit is a link to /var/share/audit.
Fix: F-51643r3_fix
The root role is required. Determine the location of the local audit trail files. # pfexec auditconfig -getplugin audit_binfile Plugin: audit_binfile (active) Attributes: p_dir=/var/audit;p_fsize=4M;p_minfree=1 In this example, the audit files can be found in /var/audit. Change the permissions on the audit trail files and the audit directory. # chmod 640 /var/share/audit/* # chmod 750 /var/share/audit Note: The default Solaris 11 location for /var/audit is a link to /var/share/audit.
- RMF Control
- SI-11
- Severity
- L
- CCI
- CCI-001314
- Version
- SOL-11.1-070240
- Vuln IDs
-
- V-48033
- Rule IDs
-
- SV-60905r2_rule
Checks: C-50469r3_chk
Check the permissions of the /var/adm/messages file: # ls -l /var/adm/messages Check the permissions of the /var/adm directory: # ls -ld /var/adm If the owner and group of /var/adm/messages is not root and the permissions are not 640, this is a finding. If the owner of /var/adm is not root, group is not sys, and the permissions are not 750, this is a finding.
Fix: F-51645r2_fix
The root role is required. Change the permissions and owner on the /var/adm/messages file: # chmod 640 /var/adm/messages # chown root /var/adm/messages # chgrp root /var/adm/messages Change the permissions and owner on the /var/adm directory: # chmod 750 /var/adm # chown root /var/adm # chgrp sys /var/adm
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SOL-11.1-070220
- Vuln IDs
-
- V-48035
- Rule IDs
-
- SV-60907r1_rule
Checks: C-50471r1_chk
Identify any users with GID of 0. # awk -F: '$4 == 0' /etc/passwd # awk -F: '$3 == 0' /etc/group Confirm the only account with a group id of 0 is root. If the root account is not the only account with GID of 0, this is a finding.
Fix: F-51647r1_fix
The root role is required. Change the default GID of non-root accounts to a valid GID other than 0.
- RMF Control
- CM-6
- Severity
- L
- CCI
- CCI-000366
- Version
- SOL-11.1-070210
- Vuln IDs
-
- V-48037
- Rule IDs
-
- SV-60909r2_rule
Checks: C-50473r2_chk
The root role is required. Identify all files with extended attributes. # find / \( -fstype nfs -o -fstype cachefs -o -fstype autofs \ -o -fstype ctfs -o -fstype mntfs -o -fstype objfs \ -o -fstype proc \) -prune -o -xattr -ls If output is produced, this is a finding.
Fix: F-51649r1_fix
The root role is required. Correct or justify any items discovered in the Check step. Determine the existence of any files having extended file attributes, and determine the best course of action in accordance with site policy. Remove the files or the extended attributes.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SOL-11.1-070200
- Vuln IDs
-
- V-48039
- Rule IDs
-
- SV-60911r1_rule
Checks: C-50475r1_chk
The root role is required. Identify all files that are owned by a user or group not listed in /etc/passwd or /etc/group # find / \( -fstype nfs -o -fstype cachefs -o -fstype autofs \ -o -fstype ctfs -o -fstype mntfs -o -fstype objfs \ -o -fstype proc \) -prune \( -nouser -o -nogroup \) -ls If output is produced, this is a finding.
Fix: F-51651r1_fix
The root role is required. Correct or justify any items discovered in the Check step. Determine the existence of any files that are not attributed to current users or groups on the system, and determine the best course of action in accordance with site policy. Remove the files and directories or change their ownership.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SOL-11.1-040160
- Vuln IDs
-
- V-48043
- Rule IDs
-
- SV-60915r1_rule
Checks: C-50479r1_chk
Check the SLEEPTIME parameter in the /etc/default/login file. # grep ^SLEEPTIME /etc/default/login If the output is not SLEEPTIME=4 or more, this is a finding.
Fix: F-51655r1_fix
The root role is required. # pfedit the /etc/default/login Locate the line containing: SLEEPTIME Change the line to read: SLEEPTIME=4
- RMF Control
- AC-11
- Severity
- M
- CCI
- CCI-000056
- Version
- SOL-11.1-040170
- Vuln IDs
-
- V-48045
- Rule IDs
-
- SV-60917r4_rule
Checks: C-50481r5_chk
If the system is not running XWindows, this check does not apply. Determine if the screen saver timeout is configured properly. # grep "^\*timeout:" /usr/share/X11/app-defaults/XScreenSaver If the output is not: *timeout: 0:15:00 or a shorter time interval, this is a finding. # grep "^\*lockTimeout:" /usr/share/X11/app-defaults/XScreenSaver If the output is not: *lockTimeout: 0:00:05 or a shorter time interval, this is a finding. # grep "^\*lock:" /usr/share/X11/app-defaults/XScreenSaver If the output is not: *lock: True this is a finding. For each existing user, check the configuring of their personal .xscreensaver file. # grep "^timeout:" $HOME/.xscreensaver If the output is not: timeout: 0:15:00 or a shorter time interval, this is a finding. # grep "^lockTimeout:" $HOME/.xscreensaver If the output is not: lockTimeout: 0:00:05 or a shorter time interval, this is a finding. # grep "^lock:" $HOME/.xscreensaver If the output is not: lock: True this is a finding.
Fix: F-51657r3_fix
The root role is required. Edit the global screensaver configuration file to ensure 15 minute screen lock. # pfedit /usr/share/X11/app-defaults/XScreenSaver Find the timeout control lines and change them to read: *timeout: 0:15:00 *lockTimeout: 0:00:05 *lock: True For each user on the system, edit their local $HOME/.xscreensaver file and change the timeout values. # pfedit $HOME/.xscreensaver Find the timeout control lines and change them to read: timeout: 0:15:00 lockTimeout: 0:00:05 lock: True
- RMF Control
- AC-11
- Severity
- M
- CCI
- CCI-000057
- Version
- SOL-11.1-040180
- Vuln IDs
-
- V-48047
- Rule IDs
-
- SV-60919r2_rule
Checks: C-50483r2_chk
If the system is not running XWindows, this check does not apply. Determine if the screen saver timeout is configured properly. # grep "^\*timeout:" /usr/share/X11/app-defaults/XScreenSaver If the output is not: *timeout: 0:15:00 this is a finding. # grep "^\*lockTimeout:" /usr/share/X11/app-defaults/XScreenSaver If the output is not: *lockTimeout: 0:00:00 this is a finding. # grep "^\*lock:" /usr/share/X11/app-defaults/XScreenSaver If the output is not: *lock: True this is a finding. For each existing user, check the configuration of their personal .xscreensaver file. # grep "^lock:" $HOME/.xscreensaver If the output is not: *lock: True this is a finding. grep "^lockTimeout:" $HOME/.xscreensaver If the output is not: *lockTimeout: 0:15:00 this is a finding.
Fix: F-51659r1_fix
The root role is required. Edit the global screensaver configuration file to ensure 15 minute screen lock. # pfedit /usr/share/X11/app-defaults/XScreenSaver Find the timeout control lines and change them to read: *timeout: 0:15:00 *lockTimeout:0:15:00 *lock: True For each user on the system, edit their local $HOME/.xscreensaver file and change the timeout values. # pfedit $HOME/.xscreensaver Find the timeout control lines and change them to read: timeout: 0:15:00 lockTimeout:0:15:00 lock: True
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SOL-11.1-040190
- Vuln IDs
-
- V-48053
- Rule IDs
-
- SV-60925r1_rule
Checks: C-50485r1_chk
Check /etc/default/passwd for dictionary check configuration. # grep ^DICTION /etc/default/passwd If the DICTIONLIST or DICTIONDBDIR settings are not present and are not set to: DICTIONLIST=/usr/share/lib/dict/words DICTIONDBDIR=/var/passwd this is a finding. Determine if the target files exist. # ls -l /usr/share/lib/dict/words /var/passwd If the files defined by DICTIONLIST or DICTIONBDIR are not present or are empty, this is a finding.
Fix: F-51661r1_fix
The root role is required. # pfedit /etc/default/passwd Insert the lines: DICTIONLIST=/usr/share/lib/dict/words DICTIONDBDIR=/var/passwd Generate the password dictionary by running the mkpwdict command. # mkpwdict -s /usr/share/lib/dict/words
- RMF Control
- CM-5
- Severity
- M
- CCI
- CCI-000345
- Version
- SOL-11.1-040200
- Vuln IDs
-
- V-48055
- Rule IDs
-
- SV-60927r2_rule
Checks: C-50487r1_chk
Verify the root user is configured as a role, rather than a normal user. # userattr type root If the command does not return the word "role", this is a finding. Verify at least one local user has been assigned the root role. # grep '[:;]roles=root[^;]*' /etc/user_attr If no lines are returned, or no users are permitted to assume the root role, this is a finding.
Fix: F-51663r2_fix
The root role is required. Convert the root user into a role. # usermod -K type=role root Add the root role to authorized users' logins. # usermod -R +root [username] Remove the root role from users who should not be authorized to assume it. # usermod -R -root [username]
- RMF Control
- IA-2
- Severity
- M
- CCI
- CCI-000770
- Version
- SOL-11.1-040230
- Vuln IDs
-
- V-48057
- Rule IDs
-
- SV-60929r2_rule
Checks: C-50489r1_chk
Verify the root user is configured as a role, rather than a normal user. # userattr type root If the command does not return the word "role", this is a finding. Verify at least one local user has been assigned the root role. # grep '[:;]roles=root[^;]*' /etc/user_attr If no lines are returned, or no users are permitted to assume the root role, this is a finding.
Fix: F-51665r2_fix
The root role is required. Convert the root user into a role. # usermod -K type=role root Add the root role to authorized users' logins. # usermod -R +root [username] Remove the root role from users who should not be authorized to assume it. # usermod -R -root [username]
- RMF Control
- CM-6
- Severity
- L
- CCI
- CCI-000366
- Version
- SOL-11.1-070190
- Vuln IDs
-
- V-48059
- Rule IDs
-
- SV-60931r2_rule
Checks: C-50493r2_chk
The root role is required. # find / \( -fstype nfs -o -fstype cachefs -o -fstype autofs \ -o -fstype ctfs -o -fstype mntfs -o -fstype objfs \ -o -fstype proc \) -prune -o -type f -perm -4000 -o \ -perm -2000 -print Output should only be Solaris-provided files and approved customer files. Solaris-provided SUID/SGID files can be listed using the command: # pkg contents -a mode=4??? -a mode=2??? -t file -o pkg.name,path,mode Digital signatures on the Solaris Set-UID binaries can be verified with the elfsign utility, such as this example: # elfsign verify -e /usr/bin/su elfsign: verification of /usr/bin/su passed. This message indicates that the binary is properly signed. If non-vendor provided or non-approved files are included in the list, this is a finding.
Fix: F-51669r1_fix
The root role is required. Determine the existence of any set-UID programs that do not belong on the system, and work with the owners (or system administrator) to determine the best course of action in accordance with site policy.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SOL-11.1-040250
- Vuln IDs
-
- V-48061
- Rule IDs
-
- SV-60933r2_rule
Checks: C-50491r1_chk
The root role is required. Determine if the default umask is configured properly. # grep -i "^UMASK=" /etc/default/login If "UMASK=077" is not displayed, this is a finding. Check local initialization files: # cut -d: -f1 /etc/passwd | xargs -n1 -iUSER sh -c "grep umask ~USER/.*" If this command does not output a line indicating "umask 077" for each user, this is a finding.
Fix: F-51667r2_fix
The root role is required. Edit local and global initialization files containing "umask" and change them to use 077. # pfedit /etc/default/login Insert the line UMASK=077 # pfedit [user initialization file] Insert the line umask 077
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SOL-11.1-070180
- Vuln IDs
-
- V-48063
- Rule IDs
-
- SV-60935r1_rule
Checks: C-50495r1_chk
The root role is required. Check for the existence of world-writable files. # find / \( -fstype nfs -o -fstype cachefs -o -fstype autofs \ -o -fstype ctfs -o -fstype mntfs -o -fstype objfs \ -o -fstype proc \) -prune -o -type f -perm -0002 -print If output is produced, this is a finding.
Fix: F-51671r1_fix
The root role is required. Change the permissions of the files identified in the check step to remove the world-writable permission. # pfexec chmod o-w [filename]
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SOL-11.1-070170
- Vuln IDs
-
- V-48065
- Rule IDs
-
- SV-60937r1_rule
Checks: C-50497r2_chk
The root role is required. # for dir in \ `logins -ox | awk -F: '($8 == "PS") { print $6 }'`; do ls -l ${dir}/.forward 2>/dev/null done If output is produced, this is a finding.
Fix: F-51673r1_fix
The root role is required. Remove any .forward files that are found. # pfexec rm [filename]
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SOL-11.1-070160
- Vuln IDs
-
- V-48067
- Rule IDs
-
- SV-60939r2_rule
Checks: C-50499r2_chk
The root role is required. Check for the presence of user .netrc files. # for dir in \ `logins -ox | awk -F: '($8 == "PS") { print $6 }'`; do ls -l ${dir}/.netrc 2>/dev/null done If output is produced, this is a finding.
Fix: F-51675r1_fix
The root role is required. Determine if any .netrc files exist, and work with the owners to determine the best course of action in accordance with site policy.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SOL-11.1-070150
- Vuln IDs
-
- V-48069
- Rule IDs
-
- SV-60941r2_rule
Checks: C-50501r3_chk
The root role is required. Check for duplicate group names. # getent group | cut -f1 -d":" | sort -n | uniq -c |\ while read x ; do [ -z "${x}" ] && break if [ ${x} -gt 1 ]; then gids=`getent group |\ nawk -F: '($1 == n) { print $3 }' n=${y} | xargs` echo "Duplicate Group Name (${y}): ${gids}" fi done If output is produced, this is a finding.
Fix: F-51677r1_fix
The root role is required. Correct or justify any items discovered in the Check step. Determine if there are any duplicate group names, and work with their respective owners to determine the best course of action in accordance with site policy. Delete or change the group name of duplicate groups.
- RMF Control
- CM-6
- Severity
- L
- CCI
- CCI-000366
- Version
- SOL-11.1-040260
- Vuln IDs
-
- V-48071
- Rule IDs
-
- SV-60943r1_rule
Checks: C-50503r1_chk
The package service/network/ftp must be installed for this check. # pkg list service/network/ftp If the output of this command is: pkg list: no packages matching 'service/network/ftp' installed no further action is required. Determine if the FTP umask is set to 077. # egrep -i "^UMASK" /etc/proftpd.conf | awk '{ print $2 }' If 077 is not displayed, this is a finding.
Fix: F-51679r1_fix
The root role is required. # pkg list service/network/ftp If the output of this command is: pkg list: no packages matching 'service/network/ftp' installed no further action is required. Otherwise, edit the FTP configuration file. # pfedit /etc/proftpd.conf Locate the line containing: Umask Change the line to read: Umask 077
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SOL-11.1-070140
- Vuln IDs
-
- V-48073
- Rule IDs
-
- SV-60945r1_rule
Checks: C-50505r1_chk
The root role is required. Identify any duplicate user names. # getent passwd | awk -F: '{print $1}' | uniq -d If output is produced, this is a finding.
Fix: F-51681r1_fix
The root role is required. Correct or justify any items discovered in the Check step. Determine if there are any duplicate user names, and work with their respective owners to determine the best course of action in accordance with site policy. Delete or change the user name of duplicate users.
- RMF Control
- CM-6
- Severity
- L
- CCI
- CCI-000366
- Version
- SOL-11.1-040270
- Vuln IDs
-
- V-48075
- Rule IDs
-
- SV-60947r2_rule
Checks: C-50507r1_chk
Determine if "mesg n" is the default for users. # grep "^mesg" /etc/.login # grep "^mesg" /etc/profile If either of these commands produces a line: mesg y this is a finding. For each existing user on the system, enter the command: # mesg If the command output is: is y this is a finding.
Fix: F-51683r2_fix
The root role is required. Edit the default profile configuration files. # pfedit /etc/profile # pfedit /etc/.login In each file add a new line: mesg n For each user on the system, enter the command: # mesg n
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SOL-11.1-070130
- Vuln IDs
-
- V-48077
- Rule IDs
-
- SV-60949r4_rule
Checks: C-50509r4_chk
The root role is required. Check that reserved UIDs are not assigned to non-system users. # logins -so | awk -F: '{ print $1 }' | while read user; do found=0 for tUser in root daemon bin sys adm dladm netadm netcfg \ ftp dhcpserv sshd smmsp gdm zfssnap aiuser \ polkitd ikeuser lp openldap webservd unknown \ pkg5srv nobody noaccess nobody4; do if [ ${user} = ${tUser} ]; then found=1 fi done if [ $found -eq 0 ]; then echo "Invalid User with Reserved UID: ${user}" fi done If output is produced, this is a finding.
Fix: F-51685r1_fix
The root role is required. Correct or justify any items discovered in the Check step. Determine if there are any accounts using these reserved UIDs, and work with their owners to determine the best course of action in accordance with site policy. This may require deleting users or changing UIDs for users.
- RMF Control
- AC-2
- Severity
- M
- CCI
- CCI-000017
- Version
- SOL-11.1-040280
- Vuln IDs
-
- V-48079
- Rule IDs
-
- SV-60951r1_rule
Checks: C-50511r1_chk
Determine whether the 35-day inactivity lock is configured properly. # useradd -D | xargs -n 1 | grep inactive |\ awk -F= '{ print $2 }' If the command returns a result other than 35, this is a finding. The root role is required for the "logins" command. For each configured user name and role name on the system, determine whether a 35-day inactivity period is configured. Replace [username] with an actual user name or role name. # logins -axo -l [username] | awk -F: '{ print $13 }' If these commands provide output other than 35, this is a finding.
Fix: F-51687r1_fix
The root role is required. Perform the following to implement the recommended state: # useradd -D -f 35 To set this policy on a user account, use the command(s): # usermod -f 35 [username] To set this policy on a role account, use the command(s): # rolemod -f 35 [name]
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SOL-11.1-070120
- Vuln IDs
-
- V-48081
- Rule IDs
-
- SV-60953r1_rule
Checks: C-50513r4_chk
The root role is required. Check that group IDs are unique. # getent group | cut -f3 -d":" | sort -n | uniq -c |\ while read x ; do [ -z "${x}" ] && break set - $x if [ $1 -gt 1 ]; then grps=`getent group | nawk -F: '($3 == n) { print $1 }' n=$2 | xargs` echo "Duplicate GID ($2): ${grps}" fi done If output is produced, this is a finding.
Fix: F-51689r1_fix
The root role is required. Work with each respective group owner to remediate this issue and ensure that the group ownership of their files are set to an appropriate value.
- RMF Control
- IA-4
- Severity
- M
- CCI
- CCI-000795
- Version
- SOL-11.1-040290
- Vuln IDs
-
- V-48083
- Rule IDs
-
- SV-60955r1_rule
Checks: C-50515r1_chk
Determine whether the 35-day inactivity lock is configured properly. # useradd -D | xargs -n 1 | grep inactive |\ awk -F= '{ print $2 }' If the command returns a result other than 35, this is a finding. The root role is required for the "logins" command. For each configured user name and role name on the system, determine whether a 35-day inactivity period is configured. Replace [username] with an actual user name or role name. # logins -axo -l [username] | awk -F: '{ print $13 }' If these commands provide output other than 35, this is a finding.
Fix: F-51691r1_fix
The root role is required. Perform the following to implement the recommended state: # useradd -D -f 35 To set this policy on a user account, use the command(s): # usermod -f 35 [username] To set this policy on a role account, use the command(s): # rolemod -f 35 [name]
- RMF Control
- AC-2
- Severity
- M
- CCI
- CCI-001682
- Version
- SOL-11.1-040300
- Vuln IDs
-
- V-48085
- Rule IDs
-
- SV-60957r1_rule
Checks: C-50517r1_chk
Determine whether the 35-day inactivity lock is configured properly. # useradd -D | xargs -n 1 | grep inactive |\ awk -F= '{ print $2 }' If the command returns a result other than 35, this is a finding. The root role is required for the "logins" command. For each configured user name and role name on the system, determine whether a 35-day inactivity period is configured. Replace [username] with an actual user name or role name. # logins -axo -l [username] | awk -F: '{ print $13 }' If these commands provide output other than 35, this is a finding.
Fix: F-51693r1_fix
The root role is required. Perform the following to implement the recommended state: # useradd -D -f 35 To set this policy on a user account, use the command(s): # usermod -f 35 [username] To set this policy on a role account, use the command(s): # rolemod -f 35 [name]
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SOL-11.1-040310
- Vuln IDs
-
- V-48087
- Rule IDs
-
- SV-60959r1_rule
Checks: C-50519r1_chk
Determine if terminal login services are disabled. # svcs -Ho state svc:/system/console-login:terma # svcs -Ho state svc:/system/console-login:termb If the system/console-login services are not "disabled", this is a finding.
Fix: F-51695r1_fix
The Service Operator profile is required. Disable serial terminal services. # pfexec svcadm disable svc:/system/console-login:terma # pfexec svcadm disable svc:/system/console-login:termb
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SOL-11.1-040320
- Vuln IDs
-
- V-48089
- Rule IDs
-
- SV-60961r1_rule
Checks: C-50521r1_chk
Determine if "nobody" access for keyserv is enabled. # grep "^ENABLE_NOBODY_KEYS=" /etc/default/keyserv If the output of the command is not: ENABLE_NOBODY_KEYS=NO this is a finding.
Fix: F-51697r1_fix
The root role is required. Modify the /etc/default/keyserv file. # pfedit /etc/default/keyserv Locate the line: #ENABLE_NOBODY_KEYS=YES Change it to: ENABLE_NOBODY_KEYS=NO
- RMF Control
- IA-8
- Severity
- M
- CCI
- CCI-000804
- Version
- SOL-11.1-070110
- Vuln IDs
-
- V-48091
- Rule IDs
-
- SV-60963r1_rule
Checks: C-50523r1_chk
The root role is required. Check that there are no duplicate UIDs. # logins -d If output is produced, this is a finding.
Fix: F-51699r1_fix
The root role is required. Determine if there exists any users who share a common UID, and work with those users to determine the best course of action in accordance with site policy. Change user account names and UID or delete accounts, so each account has a unique name and UID.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SOL-11.1-040330
- Vuln IDs
-
- V-48093
- Rule IDs
-
- SV-60965r1_rule
Checks: C-50525r1_chk
Determine if X11 Forwarding is enabled. # grep "^X11Forwarding" /etc/ssh/sshd_config If the output of this command is not: X11Forwarding no this is a finding.
Fix: F-51701r1_fix
The root role is required. Modify the sshd_config file. # pfedit /etc/ssh/sshd_config Locate the line containing: X11Forwarding Change it to: X11Forwarding no Restart the SSH service. # svcadm restart svc:/network/ssh
- RMF Control
- IA-2
- Severity
- M
- CCI
- CCI-000764
- Version
- SOL-11.1-070100
- Vuln IDs
-
- V-48095
- Rule IDs
-
- SV-60967r1_rule
Checks: C-50527r1_chk
The root role is required. Check that there are no duplicate UIDs. # logins -d If output is produced, this is a finding.
Fix: F-51703r1_fix
The root role is required. Determine if there exists any users who share a common UID, and work with those users to determine the best course of action in accordance with site policy. Change user account names and UID or delete accounts, so each account has a unique name and UID.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SOL-11.1-070090
- Vuln IDs
-
- V-48097
- Rule IDs
-
- SV-60969r2_rule
Checks: C-50529r5_chk
The root role is required. Check that home directories are owned by the correct user. # export IFS=":"; logins -uxo | while read user uid group gid gecos home rest; do result=$(find ${home} -type d -prune \! -user $user -print 2>/dev/null); if [ ! -z "${result}" ]; then echo "User: ${user}\tOwner: $(ls -ld $home | awk '{ print $3 }')"; fi; done If any output is produced, this is a finding.
Fix: F-51705r1_fix
The root role is required. Correct the owner of any directory that does not match the password file entry for that user. # chown [user] [home directory]
- RMF Control
- CM-6
- Severity
- L
- CCI
- CCI-000366
- Version
- SOL-11.1-040340
- Vuln IDs
-
- V-48099
- Rule IDs
-
- SV-60971r1_rule
Checks: C-50531r1_chk
Determine if consecutive login attempts are limited to 3. # grep "^MaxAuthTries" /etc/ssh/sshd_config If the output of this command is not: MaxAuthTries 6 MaxAuthTriesLog 6 this is a finding. Note: Solaris SSH MaxAuthTries of 6 maps to 3 actual failed attempts.
Fix: F-51707r1_fix
The root role is required. Modify the sshd_config file. # pfedit /etc/ssh/sshd_config Locate the line containing: MaxAuthTries Change it to: MaxAuthTries 6 Restart the SSH service. # svcadm restart svc:/network/ssh Note: Solaris SSH MaxAuthTries of 6 maps to 3 actual failed attempts.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SOL-11.1-040350
- Vuln IDs
-
- V-48101
- Rule IDs
-
- SV-60973r1_rule
Checks: C-50533r1_chk
Determine if rhost-based authentication is enabled. # grep "^IgnoreRhosts" /etc/ssh/sshd_config If the output is produced and it is not: IgnoreRhosts yes this is a finding. If the IgnoreRhosts line does not exist in the file, the default setting of "Yes" is automatically used and there is no finding.
Fix: F-51709r1_fix
The root role is required. Modify the sshd_config file # pfedit /etc/ssh/sshd_config Locate the line containing: IgnoreRhosts Change it to: IgnoreRhosts yes Restart the SSH service. # svcadm restart svc:/network/ssh This action will only set the IgnoreRhosts line if it already exists in the file to ensure that it is set to the proper value. If the IgnoreRhosts line does not exist in the file, the default setting of "Yes" is automatically used, so no additional changes are needed.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SOL-11.1-040360
- Vuln IDs
-
- V-48103
- Rule IDs
-
- SV-60975r1_rule
Checks: C-50537r1_chk
Determine if root login is disabled for the SSH service. # grep "^PermitRootLogin" /etc/ssh/sshd_config If the output of this command is not: PermitRootLogin no this is a finding.
Fix: F-51713r1_fix
The root role is required. Modify the sshd_config file # pfedit /etc/ssh/sshd_config Locate the line containing: PermitRootLogin Change it to: PermitRootLogin no Restart the SSH service. # svcadm restart svc:/network/ssh
- RMF Control
- CM-6
- Severity
- L
- CCI
- CCI-000366
- Version
- SOL-11.1-070080
- Vuln IDs
-
- V-48105
- Rule IDs
-
- SV-60977r2_rule
Checks: C-50535r3_chk
The root role is required. Check if a GUI is installed. # pkg info gdm # pkg info coherence-26 If neither package is installed on the system, then no GUI is present. Check that all users' home directories exist. # pwck Accounts with no home directory will output "Login directory not found". If no GUI is present, then "gdm" and "upnp" accounts should generate errors. On all systems, "uucp" and "nuucp" should generate errors. If users' home directories do not exist, this is a finding.
Fix: F-51711r1_fix
The root role is required. Work with users identified in the check step to determine the best course of action in accordance with site policy. This generally means deleting the user account or creating a valid home directory.
- RMF Control
- CM-6
- Severity
- H
- CCI
- CCI-000366
- Version
- SOL-11.1-040370
- Vuln IDs
-
- V-48107
- Rule IDs
-
- SV-60979r1_rule
Checks: C-50539r1_chk
Determine if empty/null passwords are allowed for the SSH service. # grep "^PermitEmptyPasswords" /etc/ssh/sshd_config If the output of this command is not: PermitEmptyPasswords no this is a finding.
Fix: F-51715r1_fix
The root role is required. Modify the sshd_config file # pfedit /etc/ssh/sshd_config Locate the line containing: PermitEmptyPasswords/ Change it to: PermitEmptyPasswords/ no Restart the SSH service. # svcadm restart svc:/network/ssh
- RMF Control
- CM-6
- Severity
- L
- CCI
- CCI-000366
- Version
- SOL-11.1-070070
- Vuln IDs
-
- V-48109
- Rule IDs
-
- SV-60981r1_rule
Checks: C-50541r1_chk
The root role is required. Determine if each user has a valid home directory. # logins -xo | while read line; do user=`echo ${line} | awk -F: '{ print $1 }'` home=`echo ${line} | awk -F: '{ print $6 }'` if [ -z "${home}" ]; then echo ${user} fi done If output is produced, this is a finding.
Fix: F-51717r1_fix
The root role is required. Correct or justify any items discovered in the check step. Determine if there exists any users who are in passwd but do not have a home directory, and work with those users to determine the best course of action in accordance with site policy. This generally means deleting the user or creating a valid home directory.
- RMF Control
- SC-10
- Severity
- L
- CCI
- CCI-001133
- Version
- SOL-11.1-040380
- Vuln IDs
-
- V-48111
- Rule IDs
-
- SV-60983r1_rule
Checks: C-50543r1_chk
Determine if SSH is configured to disconnect sessions after 10 minutes of inactivity. # grep ClientAlive /etc/ssh/sshd_config If the output of this command is not: ClientAliveInterval 600 ClientAliveCountMax 0 this is a finding.
Fix: F-51719r1_fix
The root role is required. Configure the system to disconnect SSH sessions after 10 minutes of inactivity. Modify the sshd_config file # pfedit /etc/ssh/sshd_config Locate the lines containing: ClientAliveInterval ClientAliveCountMax Change them to: ClientAliveInterval 600 ClientAliveCountMax 0 Restart the SSH service. # svcadm restart svc:/network/ssh
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SOL-11.1-040390
- Vuln IDs
-
- V-48113
- Rule IDs
-
- SV-60985r3_rule
Checks: C-50545r3_chk
Note: This is the location for Solaris 11.1. For earlier versions, the information is in /etc/pam.conf. Determine if host-based authentication services are enabled. # grep -v '^#' /etc/pam.conf /etc/pam.d/* | grep -c 'pam_rhosts_auth.so.1' If the returned result is not 0 (zero), this is a finding.
Fix: F-51721r3_fix
Note: This is the location for Solaris 11.1. For earlier versions, the information is in /etc/pam.conf. The root role is required. # ls -l /etc/pam.d to identify the various configuration files used by PAM. Search each file for the pam_rhosts_auth.so.1 entry. # grep pam_rhosts_auth.so.1 [filename] Identify the file with the line pam_hosts_auth.so.1 in it. # pfedit [filename] Insert a comment character (#) at the beginning of the line containing "pam_hosts_auth.so.1".
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SOL-11.1-070060
- Vuln IDs
-
- V-48115
- Rule IDs
-
- SV-60987r1_rule
Checks: C-50547r1_chk
The root role is required. Check that groups are configured correctly. # logins -xo | awk -F: '($3 == "") { print $1 }' If output is produced, this is a finding.
Fix: F-51723r1_fix
The root role is required. Correct or justify any items discovered in the Audit step. Determine if any groups are in passwd but not in group, and work with those users or group owners to determine the best course of action in accordance with site policy.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SOL-11.1-040400
- Vuln IDs
-
- V-48117
- Rule IDs
-
- SV-60989r1_rule
Checks: C-50549r3_chk
The root role is required. Determine if the FTP server package is installed: # pkg list service/network/ftp If the output of this command is: pkg list: no packages matching 'service/network/ftp' installed no further action is required. If the FTP server is installed, determine if FTP access is restricted. # for user in `logins -s | awk '{ print $1 }'` \ aiuser noaccess nobody nobody4; do grep -w "${user}" /etc/ftpd/ftpusers >/dev/null 2>&1 if [ $? != 0 ]; then echo "User '${user}' not in /etc/ftpd/ftpusers." fi done If output is returned, this is a finding.
Fix: F-51725r2_fix
The root role is required. Determine if the FTP server package is installed: # pkg list service/network/ftp If the output of this command is: pkg list: no packages matching 'service/network/ftp' installed no further action is required. # for user in `logins -s | awk '{ print $1 }'` \ aiuser noaccess nobody nobody4; do $(echo $user >> /etc/ftpd/ftpusers) done # sort -u /etc/ftpd/ftpusers > /etc/ftpd/ftpusers.temp # mv /etc/ftpd/ftpusers.temp /etc/ftpd/ftpusers
- RMF Control
- CM-6
- Severity
- H
- CCI
- CCI-000366
- Version
- SOL-11.1-070050
- Vuln IDs
-
- V-48119
- Rule IDs
-
- SV-60991r1_rule
Checks: C-50551r2_chk
The root role is required. Check for the presence of .rhosts files. # for dir in \ `logins -ox | awk -F: '($8 == "PS") { print $6 }'`; do find ${dir}/.rhosts -type f -ls 2>/dev/null done If output is produced, this is a finding.
Fix: F-51727r1_fix
The root role is required. Remove any .rhosts files found. # rm [file name]
- RMF Control
- CM-6
- Severity
- H
- CCI
- CCI-000366
- Version
- SOL-11.1-040410
- Vuln IDs
-
- V-48121
- Rule IDs
-
- SV-60993r1_rule
Checks: C-50553r1_chk
Determine if autologin is enabled for the GNOME desktop. # egrep "auth|account" /etc/pam.d/gdm-autologin | grep -vc ^# If the command returns other than "0", this is a finding.
Fix: F-51729r1_fix
The root role is required. Modify the /etc/pam.d/gdm-autologin file. # pfedit /etc/pam.d/gdm-autologin Locate the lines: auth required pam_unix_cred.so.1 auth sufficient pam_allow.so.1 account sufficient pam_allow.so.1 Change the lines to read: #auth required pam_unix_cred.so.1 #auth sufficient pam_allow.so.1 #account sufficient pam_allow.so.1
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SOL-11.1-070040
- Vuln IDs
-
- V-48123
- Rule IDs
-
- SV-60995r1_rule
Checks: C-50555r2_chk
The root role is required. Check that permissions on user .netrc files are 750 or less permissive. # for dir in \ `logins -ox | awk -F: '($8 == "PS") { print $6 }'`; do find ${dir}/.netrc -type f \( \ -perm -g+r -o -perm -g+w -o -perm -g+x -o \ -perm -o+r -o -perm -o+w -o -perm -o+x \) \ -ls 2>/dev/null done If output is produced, this is a finding.
Fix: F-51731r1_fix
The root role is required. Change the permissions on users' .netrc files to 750 or less permissive. # chmod 750 [file name]
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SOL-11.1-040420
- Vuln IDs
-
- V-48125
- Rule IDs
-
- SV-60997r3_rule
Checks: C-50557r3_chk
Check that "at" and "cron" users are configured correctly. # ls /etc/cron.d/cron.deny If cron.deny exists, this is a finding. # ls /etc/cron.d/at.deny If at.deny exists, this is a finding. # cat /etc/cron.d/cron.allow cron.allow should have a single entry for "root". If any accounts other than root that are listed and they are not properly documented with the IA staff, this is a finding. # wc -l /etc/cron.d/at.allow | awk '{ print $1 }' If the output is non-zero, this is a finding.
Fix: F-51733r2_fix
The root role is required. Modify the cron configuration files. # mv /etc/cron.d/cron.deny /etc/cron.d/cron.deny.temp # mv /etc/cron.d/at.deny /etc/cron.d/at.deny.temp # echo root > /etc/cron.d/cron.allow # cp /dev/null /etc/cron.d/at.allow # chown root:root /etc/cron.d/cron.allow /etc/cron.d/at.allow # chmod 400 /etc/cron.d/cron.allow /etc/cron.d/at.allow
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SOL-11.1-040430
- Vuln IDs
-
- V-48127
- Rule IDs
-
- SV-60999r1_rule
Checks: C-50559r1_chk
This check applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this check applies. Determine if root login is restricted to the console. # grep "^CONSOLE=/dev/console" /etc/default/login If the output of this command is not: CONSOLE=/dev/console this is a finding.
Fix: F-51735r1_fix
The root role is required. Modify the /etc/default/login file # pfedit /etc/default/login Locate the line containing: CONSOLE Change it to read: CONSOLE=/dev/console
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SOL-11.1-070030
- Vuln IDs
-
- V-48129
- Rule IDs
-
- SV-61001r1_rule
Checks: C-50561r1_chk
The root role is required. Ensure that the permissions on user "." files are 750 or less permissive.. # for dir in \ `logins -ox | awk -F: '($8 == "PS") { print $6 }'`; do find ${dir}/.[A-Za-z0-9]* \! -type l \ \( -perm -20 -o -perm -02 \) -ls done If output is produced, this is a finding.
Fix: F-51737r1_fix
The root role is required. Change the permissions on users' "." files to 750 or less permissive. # chmod 750 [file name]
- RMF Control
- AC-9
- Severity
- L
- CCI
- CCI-000052
- Version
- SOL-11.1-040450
- Vuln IDs
-
- V-48131
- Rule IDs
-
- SV-61003r1_rule
Checks: C-50563r1_chk
Determine if last login will be printed for SSH users. # grep PrintLastLog /etc/ssh/sshd_config If PrintLastLog is found, not preceded with a "#" sign, and is set to "no", this is a finding. PrintLastLog should either not exist (defaulting to yes) or exist and be set to yes.
Fix: F-51739r1_fix
The root role is required for this action. # pfedit /etc/ssh/sshd_config Locate the line containing: PrintLastLog no and place a comment sign ("# ")at the beginning of the line or delete the line # PrintLastLog no Restart the ssh service # pfexec svcadm restart svc:/network/ssh
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SOL-11.1-070020
- Vuln IDs
-
- V-48133
- Rule IDs
-
- SV-61005r1_rule
Checks: C-50565r1_chk
The root role is required. Check that the permissions on users' home directories are 750 or less permissive. # for dir in `logins -ox |\ awk -F: '($8 == "PS") { print $6 }'`; do find ${dir} -type d -prune \( -perm -g+w -o \ -perm -o+r -o -perm -o+w -o -perm -o+x \) -ls done If output is created, this is finding.
Fix: F-51741r1_fix
The root role is required. Change the permissions on users' directories to 750 or less permissive. # chmod 750 [directory name]
- RMF Control
- AC-11
- Severity
- M
- CCI
- CCI-000058
- Version
- SOL-11.1-040460
- Vuln IDs
-
- V-48135
- Rule IDs
-
- SV-61007r1_rule
Checks: C-50567r2_chk
Determine whether the lock screen function works correctly. In the Gnome desktop System > Lock Screen, check that the screen locks and displays the password prompt. Check that "Disable Screensave"r is not selected in the Gnome Screensaver preferences. If the screen does not lock or the "Disable Screensaver" option is selected, this is a finding.
Fix: F-51743r2_fix
User-initiated session lock is accessible from the Gnome graphical desktop System > Lock Screen Menu item. However, the user has the option via the "System>Preferences>Screensaver" item to disable screensaver lock. Ensure that mode is set to "Blank Screen only."
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SOL-11.1-070010
- Vuln IDs
-
- V-48137
- Rule IDs
-
- SV-61009r1_rule
Checks: C-50569r1_chk
The root role is required. Identify all world-writable directories without the "sticky bit" set. # find / \( -fstype nfs -o -fstype cachefs -o -fstype autofs \ -o -fstype ctfs -o -fstype mntfs -o -fstype objfs \ -o -fstype proc \) -prune -o -type d \( -perm -0002 \ -a ! -perm -1000 \) -ls Output of this command identifies world-writable directories without the "sticky bit" set. If output is created, this is a finding.
Fix: F-51745r1_fix
The root role is required. Ensure that the "sticky bit" is set on any directories identified during the check steps. # chmod +t [directory name]
- RMF Control
- AC-11
- Severity
- M
- CCI
- CCI-000060
- Version
- SOL-11.1-040470
- Vuln IDs
-
- V-48139
- Rule IDs
-
- SV-61011r1_rule
Checks: C-50571r2_chk
Using the: System>Preferences>Screensaver Menu item the user can select other screens or disable screensaver. Check that "Disable Screensaver" is not selected in the Gnome Screensaver preferences. If "Disable Screensaver" is selected or "Blank Screen Only" is not selected, this is a finding.
Fix: F-51747r2_fix
Using the: System>Preferences>Screensaver Click on Mode's pull-down and select: Blank Screen Only. Ensure that "Blank Screen Only" is selected.
- RMF Control
- SC-8
- Severity
- M
- CCI
- CCI-001127
- Version
- SOL-11.1-060190
- Vuln IDs
-
- V-48141
- Rule IDs
-
- SV-61013r1_rule
Checks: C-50573r1_chk
The operator shall determine if IPsec is being used to encrypt data for activities such as cluster interconnects or other non-SSH, SFTP data connections. On both systems review the file /etc/inet/ipsecinit.conf. Ensure that connections between hosts are configured properly in this file per the Solaris 11 documentation. Check that the IPsec policy service is online: # svcs svc:/network/ipsec/policy:default If the IPsec service is not online, this is a finding. If encrypted protocols are not used between systems, this is a finding.
Fix: F-51749r1_fix
The Service Management profile is required. Configure IPsec encrypted tunneling between two systems. On both systems review the file /etc/inet/ipsecinit.conf. Ensure that connections between hosts are configured properly in this file per the Solaris 11 documentation. Ensure that the IPsec policy service is online: Enable the IPsec service: # svcadm enable svc:/network/ipsec/policy:default
- RMF Control
- CM-6
- Severity
- H
- CCI
- CCI-000366
- Version
- SOL-11.1-040480
- Vuln IDs
-
- V-48143
- Rule IDs
-
- SV-61015r1_rule
Checks: C-50575r1_chk
Determine if the system is enforcing a policy that passwords are required. # grep ^PASSREQ /etc/default/login If the command does not return: PASSREQ=YES this is a finding.
Fix: F-51751r1_fix
The root role is required. Modify the /etc/default/login file. # pfedit /etc/default/login Insert the line: PASSREQ=YES
- RMF Control
- AU-9
- Severity
- L
- CCI
- CCI-001350
- Version
- SOL-11.1-060180
- Vuln IDs
-
- V-48145
- Rule IDs
-
- SV-61017r1_rule
Checks: C-50577r1_chk
The Audit Configuration and the Audit Control profiles are required. This check applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this check applies. Determine if audit log encryption is required by your organization. If not required, this check does not apply. Determine where the audit logs are stored and whether the file system is encrypted. # pfexec auditconfig -getplugin audit_binfile The p_dir attribute lists the location of the audit log filesystem. The default location for Solaris 11.1 is /var/audit. /var/audit is a link to /var/share/audit which, by default, is mounted on rpool/VARSHARE. Determine if this is encrypted: # zfs get encryption rpool/VARSHARE If the file system where audit logs are stored reports "encryption off", this is a finding.
Fix: F-51753r1_fix
The ZFS File System Management and ZFS Storage Management profiles are required. This action applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this action applies. The Audit Configuration and the Audit Control profiles are required. If necessary, create a new ZFS pool to store the encrypted audit logs. # pfexec zpool create auditp mirror [device] [device] Create an encryption key: # pktool genkey keystore=file outkey=/[filename] keytype=aes keylen=256 Create a new file system to store the audit logs with encryption enabled. Use the file name created in the previous step as the keystore. # pfexec zfs create -o encryption=aes-256-ccm -o keysource=raw,file:///[filename] -o compression=on -o mountpoint=/audit auditp/auditf Configure auditing to use this encrypted directory. # pfexec auditconfig -setplugin audit_binfile p_dir=/audit/ Refresh the audit service for the setting to be applied: # pfexec audit -s
- RMF Control
- SC-7
- Severity
- M
- CCI
- CCI-001111
- Version
- SOL-11.1-040490
- Vuln IDs
-
- V-48147
- Rule IDs
-
- SV-61019r1_rule
Checks: C-50579r1_chk
Determine if the "RestrictOutbound" profile is configured properly: # profiles -p RestrictOutbound info If the output is not: name=RestrictOutbound desc=Restrict Outbound Connections limitpriv=zone,!net_access this is a finding. For users who are not allowed external network access, determine if a user is configured with the "RestrictOutbound" profile. # profiles -l [username] If the output does not include: [username]: RestrictOutbound this is a finding.
Fix: F-51755r2_fix
The root Role is required. Remove net_access privilege from users who may be accessing the systems externally. 1. Create an RBAC Profile with net_access restriction # profiles -p RestrictOutbound profiles:RestrictOutbound> set desc="Restrict Outbound Connections" profiles:RestrictOutbound> set limitpriv=zone,!net_access profiles:RestrictOutbound> exit 2. Assign the RBAC Profile to a user # usermod -P +RestrictOutbound [username] This prevents the user from initiating any outbound network connections.
- RMF Control
- SC-28
- Severity
- L
- CCI
- CCI-001200
- Version
- SOL-11.1-060170
- Vuln IDs
-
- V-48149
- Rule IDs
-
- SV-61021r1_rule
Checks: C-50581r1_chk
Determine if file system encryption is required by your organization. If not required, this item does not apply. Determine if file system encryption is enabled for user data sets. This check does not apply to the root, var, share, swap or dump datasets. # zfs list Using the file system name, determine if the file system is encrypted: # zfs get encryption [filesystem] If "encryption off" is listed, this is a finding.
Fix: F-51757r1_fix
The ZFS file system management profile is required. ZFS file system encryption may only be enabled on creation of the file system. If a file system must be encrypted and is not, its data should be archived, it must be removed and re-created. First, stop running applications using the file systems, archive the data, unmount, and then remove the file system. # umount [file system name] # zfs destroy [file system name] When creating ZFS file systems, ensure that they are created as encrypted file systems. # pfexec zfs create -o encryption=on [file system name] Enter passphrase for '[file system name]': xxxxxxx Enter again: xxxxxxx Store the passphrase in a safe location. The passphrase will be required to mount the file systems upon system reboot. If automated mounting is required, the passphrase must be stored in a file.
- RMF Control
- AC-10
- Severity
- L
- CCI
- CCI-000054
- Version
- SOL-11.1-040500
- Vuln IDs
-
- V-48151
- Rule IDs
-
- SV-61023r2_rule
Checks: C-50583r1_chk
Identify the organizational requirements for maximum number of sessions and which users must be restricted. If there are no requirements to limit concurrent sessions, this item does not apply. For each user requiring concurrent session restrictions, determine if that user is in the user.[username] project where [username] is the user's account username. # projects [username] | grep user If the output does not include the project user.[username], this is a finding. Determine the project membership for the user. # projects [username] If the user is a member of any project other than default, group.[groupname], or user.[username], this is a finding. Determine whether the max-tasks resource control is enabled properly. # projects -l user.[username] | grep attribs If the output does not include the text: attribs: project.max-tasks=(privileged,[MAX],deny) where [MAX] is the organization-defined maximum number of concurrent sessions, this is a finding.
Fix: F-51759r2_fix
Identify the organizational requirements for maximum number of sessions and which users must be restricted. If there are no requirements to limit concurrent sessions, this item does not apply. The Project Management profile is required. For each user requiring concurrent session restrictions, add the user to the special user.[username] project where [username] is the user's account username where [MAX] is equal to the organizational requirement. # pfexec projadd -K 'project.max-tasks=(privileged,[MAX],deny)' user.[username] Determine the project membership for the user. # projects [username] If the user is a member of any projects other than default, group.[groupname], or user.[username], remove that project from the user's account. The root role is required. # pfedit /etc/user_attr Locate the line containing the user's username. Remove any project=[projectname] entries from the fifth field. # pfedit /etc/project Locate the line containing the user's username in a project other than default, group.[groupname], or user.[username], and remove the user from the project's entry or entries from the fourth field.
- RMF Control
- SC-28
- Severity
- L
- CCI
- CCI-001199
- Version
- SOL-11.1-060160
- Vuln IDs
-
- V-48153
- Rule IDs
-
- SV-61025r1_rule
Checks: C-50585r1_chk
Determine if file system encryption is required by your organization. If not required, this item does not apply. Determine if file system encryption is enabled for user data sets. This check does not apply to the root, var, share, swap or dump datasets. # zfs list Using the file system name, determine if the file system is encrypted: # zfs get encryption [filesystem] If "encryption off" is listed, this is a finding.
Fix: F-51761r1_fix
The ZFS file system management profile is required. ZFS file system encryption may only be enabled on creation of the file system. If a file system must be encrypted and is not, its data should be archived, it must be removed and re-created. First, stop running applications using the file systems, archive the data, unmount, and then remove the file system. # umount [file system name] # zfs destroy [file system name] When creating ZFS file systems, ensure that they are created as encrypted file systems. # pfexec zfs create -o encryption=on [file system name] Enter passphrase for '[file system name]': xxxxxxx Enter again: xxxxxxx Store the passphrase in a safe location. The passphrase will be required to mount the file systems upon system reboot. If automated mounting is required, the passphrase must be stored in a file.
- RMF Control
- MP-4
- Severity
- L
- CCI
- CCI-001019
- Version
- SOL-11.1-060150
- Vuln IDs
-
- V-48155
- Rule IDs
-
- SV-61027r1_rule
Checks: C-50587r1_chk
Determine if file system encryption is required by your organization. If not required, this item does not apply. Determine if file system encryption is enabled for user data sets. This check does not apply to the root, var, share, swap or dump datasets. # zfs list Using the file system name, determine if the file system is encrypted: # zfs get encryption [filesystem] If "encryption off" is listed, this is a finding.
Fix: F-51763r1_fix
The ZFS file system management profile is required. ZFS file system encryption may only be enabled on creation of the file system. If a file system must be encrypted and is not, its data should be archived, it must be removed and re-created. First, stop running applications using the file systems, archive the data, unmount, and then remove the file system. # umount [file system name] # zfs destroy [file system name] When creating ZFS file systems, ensure that they are created as encrypted file systems. # pfexec zfs create -o encryption=on [file system name] Enter passphrase for '[file system name]': xxxxxxx Enter again: xxxxxxx Store the passphrase in a safe location. The passphrase will be required to mount the file systems upon system reboot. If automated mounting is required, the passphrase must be stored in a file.
- RMF Control
- MP-2
- Severity
- M
- CCI
- CCI-001009
- Version
- SOL-11.1-060140
- Vuln IDs
-
- V-48157
- Rule IDs
-
- SV-61029r1_rule
Checks: C-50589r1_chk
This check applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this check applies. Determine the logical node of all attached removable media: # rmformat This command lists all attached removable devices. Note the device logical node name. For example: /dev/rdsk/c8t0d0p0 Determine which zpool is mapped to the device: # zpool status Determine the file system names of the portable digital media: # zfs list | grep [poolname] Using the file system name, determine if the removal media is encrypted: # zfs get encryption [filesystem] If "encryption off" is listed, this is a finding.
Fix: F-51765r1_fix
The root role is required. Format a removable device as a ZFS encrypted file system. This action applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this action applies. The ZFS File System Management and ZFS Storage management profiles are required. Insert the removable device: # rmformat This command lists all attached removable devices. Note the device logical node name. For example: /dev/rdsk/c8t0d0p0 Create an encrypted zpool on this device using a poolname of your choice: # pfexec zpool create -O encryption=on [poolname] c8t0d0p0 Enter a passphrase and confirm the passphrase. Keep the passphrase secure. Export the zpool before removing the media: # pfexec export [poolname] It will be necessary to enter the passphrase when inserting and importing the removable media zpool: Insert the removable media # pfexec import [poolname] Only store data in the encrypted file system.
- RMF Control
- AC-17
- Severity
- M
- CCI
- CCI-000068
- Version
- SOL-11.1-060130
- Vuln IDs
-
- V-48159
- Rule IDs
-
- SV-61031r1_rule
Checks: C-50591r1_chk
All remote sessions must be conducted via encrypted services and ports. Ask the operator to document all configured external ports and protocols. If any unencrypted connections are used, this is a finding.
Fix: F-51767r2_fix
All remote sessions must be conducted via SSH and IPsec. Ensure that SSH and IPsec are the only protocols used.
- RMF Control
- SC-9
- Severity
- M
- CCI
- CCI-001132
- Version
- SOL-11.1-060120
- Vuln IDs
-
- V-48161
- Rule IDs
-
- SV-61033r1_rule
Checks: C-50593r1_chk
All remote sessions must be conducted via encrypted services and ports. Ask the operator to document all configured external ports and protocols. If any unencrypted connections are used, this is a finding.
Fix: F-51769r2_fix
All remote sessions must be conducted via SSH and IPsec. Ensure that SSH and IPsec are the only protocols used.
- RMF Control
- SC-9
- Severity
- M
- CCI
- CCI-001131
- Version
- SOL-11.1-060110
- Vuln IDs
-
- V-48163
- Rule IDs
-
- SV-61035r1_rule
Checks: C-50597r1_chk
All remote sessions must be conducted via encrypted services and ports. Ask the operator to document all configured external ports and protocols. If any unencrypted connections are used, this is a finding.
Fix: F-51771r2_fix
All remote sessions must be conducted via SSH and IPsec. Ensure that SSH and IPsec are the only protocols used.
- RMF Control
- CM-6
- Severity
- L
- CCI
- CCI-000366
- Version
- SOL-11.1-050010
- Vuln IDs
-
- V-48165
- Rule IDs
-
- SV-61037r1_rule
Checks: C-50595r1_chk
Determine if directed broadcast packet forwarding is disabled. # ipadm show-prop -p _forward_directed_broadcasts -co current ip If the output of this command is not "0", this is a finding.
Fix: F-51773r1_fix
The Network Management profile is required. Disable directed broadcast packet forwarding. # pfexec ipadm set-prop -p _forward_directed_broadcasts=0 ip
- RMF Control
- SC-9
- Severity
- M
- CCI
- CCI-001130
- Version
- SOL-11.1-060100
- Vuln IDs
-
- V-48167
- Rule IDs
-
- SV-61039r1_rule
Checks: C-50599r1_chk
All remote sessions must be conducted via encrypted services and ports. Ask the operator to document all configured external ports and protocols. If any unencrypted connections are used, this is a finding.
Fix: F-51775r2_fix
All remote sessions must be conducted via SSH and IPsec. Ensure that SSH and IPsec are the only protocols used.
- RMF Control
- CM-6
- Severity
- L
- CCI
- CCI-000366
- Version
- SOL-11.1-050020
- Vuln IDs
-
- V-48169
- Rule IDs
-
- SV-61041r1_rule
Checks: C-50601r1_chk
Determine if ICMP time stamp responses are disabled. # ipadm show-prop -p _respond_to_timestamp -co current ip If the output of both commands is not "0", this is a finding.
Fix: F-51777r1_fix
The Network Management profile is required. Disable source respond to timestamp. # pfexec ipadm set-prop -p _respond_to_timestamp=0 ip
- RMF Control
- SC-8
- Severity
- M
- CCI
- CCI-001129
- Version
- SOL-11.1-060090
- Vuln IDs
-
- V-48171
- Rule IDs
-
- SV-61043r1_rule
Checks: C-50603r1_chk
All remote sessions must be conducted via encrypted services and ports. Ask the operator to document all configured external ports and protocols. If any unencrypted connections are used, this is a finding.
Fix: F-51779r3_fix
All remote sessions must be conducted via SSH and IPsec. Ensure that SSH and IPsec are the only protocols used.
- RMF Control
- CM-6
- Severity
- L
- CCI
- CCI-000366
- Version
- SOL-11.1-050030
- Vuln IDs
-
- V-48173
- Rule IDs
-
- SV-61045r1_rule
Checks: C-50605r2_chk
Determine if response to ICMP broadcast timestamp requests is disabled. # ipadm show-prop -p _respond_to_timestamp_broadcast -co current ip If the output of this command is not "0", this is a finding.
Fix: F-51781r1_fix
The Network Management profile is required. Disable respond to timestamp broadcasts. # pfexec ipadm set-prop -p _respond_to_timestamp_broadcast=0 ip
- RMF Control
- SC-8
- Severity
- M
- CCI
- CCI-001128
- Version
- SOL-11.1-060080
- Vuln IDs
-
- V-48175
- Rule IDs
-
- SV-61047r1_rule
Checks: C-50607r1_chk
All remote sessions must be conducted via encrypted services and ports. Ask the operator to document all configured external ports and protocols. If any unencrypted connections are used, this is a finding.
Fix: F-51783r3_fix
All remote sessions must be conducted via SSH and IPsec. Ensure that SSH and IPsec are the only protocols used.
- RMF Control
- CM-6
- Severity
- L
- CCI
- CCI-000366
- Version
- SOL-11.1-050040
- Vuln IDs
-
- V-48177
- Rule IDs
-
- SV-61049r1_rule
Checks: C-50609r1_chk
Determine if the response to address mask broadcast is disabled. # ipadm show-prop -p _respond_to_address_mask_broadcast -co current ip If the output of this command is not "0", this is a finding.
Fix: F-51785r1_fix
The Network Management profile is required. Disable responses to address mask broadcast. # pfexec ipadm set-prop -p _respond_to_address_mask_broadcast=0 ip
- RMF Control
- SC-8
- Severity
- M
- CCI
- CCI-001127
- Version
- SOL-11.1-060070
- Vuln IDs
-
- V-48179
- Rule IDs
-
- SV-61051r1_rule
Checks: C-50611r1_chk
All remote sessions must be conducted via encrypted services and ports. Ask the operator to document all configured external ports and protocols. If any unencrypted connections are used, this is a finding.
Fix: F-51787r1_fix
All remote sessions must be conducted via SSH and IPsec. Ensure that SSH and IPsec are the only protocols used.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SOL-11.1-050050
- Vuln IDs
-
- V-48181
- Rule IDs
-
- SV-61053r1_rule
Checks: C-50613r1_chk
Determine if ICMP echo requests response is disabled. # ipadm show-prop -p _respond_to_echo_broadcast -co current ip If the output of this command is not "0", this is a finding.
Fix: F-51789r1_fix
The Network Management profile is required. Disable respond to echo broadcast. # pfexec ipadm set-prop -p _respond_to_echo_broadcast=0 ip
- RMF Control
- SC-13
- Severity
- M
- CCI
- CCI-001148
- Version
- SOL-11.1-060060
- Vuln IDs
-
- V-48183
- Rule IDs
-
- SV-61055r1_rule
Checks: C-50615r1_chk
This check applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this check applies. The Crypto Management profile is required to execute this command. Check to ensure that FIPS-140 encryption mode is enabled. # cryptoadm list fips-140| grep -c "is disabled" If the output of this command is not "0", this is a finding.
Fix: F-51791r1_fix
The Crypto Management profile is required to execute this command. This action applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this action applies. Enable FIPS-140 mode. # pfexec cryptoadm enable fips-140 Reboot the system as requested.
- RMF Control
- CM-6
- Severity
- L
- CCI
- CCI-000366
- Version
- SOL-11.1-050060
- Vuln IDs
-
- V-48185
- Rule IDs
-
- SV-61057r1_rule
Checks: C-50617r1_chk
Determine if response to multicast echo requests is disabled. # ipadm show-prop -p _respond_to_echo_multicast -co current ipv4 # ipadm show-prop -p _respond_to_echo_multicast -co current ipv6 If the output of all commands is not "0", this is a finding.
Fix: F-51793r1_fix
The Network Management profile is required. Disable respond to echo multi-cast for IPv4 and IPv6. # pfexec ipadm set-prop -p _respond_to_echo_multicast=0 ipv4 # pfexec ipadm set-prop -p _respond_to_echo_multicast=0 ipv6
- RMF Control
- IA-7
- Severity
- M
- CCI
- CCI-000803
- Version
- SOL-11.1-060010
- Vuln IDs
-
- V-48187
- Rule IDs
-
- SV-61059r3_rule
Checks: C-50619r1_chk
This check applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this check applies. The Crypto Management profile is required to execute this command. Check to ensure that FIPS-140 encryption mode is enabled. # cryptoadm list fips-140| grep -c "is disabled" If the output of this command is not "0", this is a finding.
Fix: F-51795r1_fix
The Crypto Management profile is required to execute this command. This action applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this action applies. Enable FIPS-140 mode. # pfexec cryptoadm enable fips-140 Reboot the system as requested.
- RMF Control
- CM-6
- Severity
- L
- CCI
- CCI-000366
- Version
- SOL-11.1-050070
- Vuln IDs
-
- V-48189
- Rule IDs
-
- SV-61061r1_rule
Checks: C-50621r1_chk
Determine if ICMP redirect messages are ignored. # ipadm show-prop -p _ignore_redirect -co current ipv4 # ipadm show-prop -p _ignore_redirect -co current ipv6 If the output of all commands is not "1", this is a finding.
Fix: F-51797r1_fix
The Network Management profile is required. Disable ignore redirects for IPv4 and IPv6. # pfexec ipadm set-prop -p _ignore_redirect=1 ipv4 # pfexec ipadm set-prop -p _ignore_redirect=1 ipv6
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SOL-11.1-050470
- Vuln IDs
-
- V-48191
- Rule IDs
-
- SV-61063r2_rule
Checks: C-50623r4_chk
Determine the zone that you are currently securing. # zonename If the command output is "global", then only the "phys" and "SR-IOV" interfaces assigned to the global zone require inspection. If using a non-Global zone, then all "phys" and "SR-IOV" interfaces assigned to the zone require inspection. Identify if this system has physical interfaces. # dladm show-link -Z | grep -v vnic LINK ZONE CLASS MTU STATE OVER net0 global phys 1500 unknown -- e1000g0 global phys 1500 up -- e1000g1 global phys 1500 up -- zoneD/net2 zoneD iptun 65515 up -- If "phys" appears in the third column, then the interface is physical. For each physical interface, determine if the network interface is Ethernet or InfiniBand: # dladm show-phys [interface name] LINK MEDIA STATE SPEED DUPLEX DEVICE [name] Ethernet unknown 0 half dnet0 The second column indicates either "Ethernet" or "Infiniband". For each physical interface, determine if the host is using ip-forwarding: # ipadm show-ifprop [interface name] | grep forwarding [name] forwarding ipv4 rw off -- off on,off [name] forwarding ipv6 rw off -- off on,off If "on" appears in the fifth column, then the interface is using ip-forwarding. For each interface, determine if the host is using SR-IOV’s Virtual Function (VF) driver: # dladm show-phys [interface name] | grep vf If the sixth column includes 'vf' in its name, it is using SR-IOV (ex: ixgbevf0). For each physical and SR-IOV interface, determine if network link protection capabilities are enabled. # dladm show-linkprop -p protection LINK PROPERTY PERM VALUE DEFAULT POSSIBLE net0 protection rw mac-nospoof, -- mac-nospoof, restricted, restricted, ip-nospoof, ip-nospoof, dhcp-nospoof dhcp-nospoof If the interface uses Infiniband and if restricted, ip-nospoof, and dhcp-nospoof do not appear in the "VALUE" column, this is a finding. If the interface uses ip-forwarding and if mac-nospoof, restricted, and dhcp-nospoof do not appear in the "VALUE" column, this is a finding. If the interface uses SR-IOV and if mac-nospoof, restricted, and dhcp-nospoof do not appear in the "VALUE" column, this is a finding. If the interface uses Ethernet without IP forwarding and if mac-nospoof, restricted, ip-nospoof, and dhcp-nospoof do not appear in the "VALUE" column, this is a finding.
Fix: F-51799r2_fix
Determine the name of the zone that you are currently securing. # zonename If the command output is "global", then only the "phys" and "SR-IOV" interfaces assigned to the global zone require configuration. If using a non-Global zone, then all "phys" and "SR-IOV" interfaces assigned to the zone require configuration. The Network Link Security profile is required. Determine which network interfaces are available and what protection modes are enabled and required. Enable link protection based on each configured network interface type. For InfiniBand: # pfexec dladm set-linkprop -p protection=restricted,ip-nospoof,dhcp-nospoof [interface name] For IP forwarding: # pfexec dladm set-linkprop -p protection=mac-nospoof,restricted,dhcp-nospoof [interface name] For SR-IOV: # pfexec dladm set-linkprop -p protection=mac-nospoof,restricted,dhcp-nospoof [interface name] For Ethernet without IP forwarding: # pfexec dladm set-linkprop -p protection=mac-nospoof,restricted,ip-nospoof,dhcp-nospoof [interface name]
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SOL-11.1-050080
- Vuln IDs
-
- V-48193
- Rule IDs
-
- SV-61065r1_rule
Checks: C-50625r1_chk
Determine if strict multihoming is configured. # ipadm show-prop -p _strict_dst_multihoming -co current ipv4 # ipadm show-prop -p _strict_dst_multihoming -co current ipv6 If the output of all commands is not "1", this is a finding.
Fix: F-51801r1_fix
The Network Management profile is required. Disable strict multihoming for IPv4 and IPv6. # pfexec ipadm set-prop -p _strict_dst_multihoming=1 ipv4 # pfexec ipadm set-prop -p _strict_dst_multihoming=1 ipv6
- RMF Control
- MA-4
- Severity
- M
- CCI
- CCI-000879
- Version
- SOL-11.1-050460
- Vuln IDs
-
- V-48195
- Rule IDs
-
- SV-61067r1_rule
Checks: C-50627r2_chk
Determine if SSH is configured to disconnect sessions after 10 minutes of inactivity. # grep ClientAlive /etc/ssh/sshd_config If the output of this command is not: ClientAliveInterval 600 ClientAliveCountMax 0 this is a finding.
Fix: F-51803r2_fix
The root role is required. Configure the system to disconnect SSH sessions after 10 minutes of inactivity. # pfedit /etc/ssh/sshd_config Insert the two lines: ClientAliveInterval 600 ClientAliveCountMax 0 Restart the SSH service with the new configuration. # svcadm restart svc:/network/ssh
- RMF Control
- CM-6
- Severity
- L
- CCI
- CCI-000366
- Version
- SOL-11.1-050090
- Vuln IDs
-
- V-48197
- Rule IDs
-
- SV-61069r3_rule
Checks: C-50629r2_chk
Determine the version of Solaris 11 in use. # cat /etc/release If the version of Solaris is earlier than Solaris 11.2, determine if ICMP redirect messages are disabled. # ipadm show-prop -p _send_redirects -co current ipv4 # ipadm show-prop -p _send_redirects -co current ipv6 If the output of all commands is not "0", this is a finding. If the version of Solaris is Solaris 11.2 or later, determine if ICMP redirect messages are disabled. # ipadm show-prop -p send_redirects -co current ipv4 # ipadm show-prop -p send_redirects -co current ipv6 If the output of all commands is not "off", this is a finding.
Fix: F-51805r2_fix
The Network Management profile is required. If the version of Solaris is earlier than Solaris 11.2, disable send redirects for IPv4 and IPv6. # pfexec ipadm set-prop -p _send_redirects=0 ipv4 # pfexec ipadm set-prop -p _send_redirects=0 ipv6 If the version of Solaris is Solaris 11.2 or later, disable send redirects for IPv4 and IPv6. # pfexec ipadm set-prop -p send_redirects=off ipv4 # pfexec ipadm set-prop -p send_redirects=off ipv6
- RMF Control
- AC-8
- Severity
- L
- CCI
- CCI-000048
- Version
- SOL-11.1-050430
- Vuln IDs
-
- V-48199
- Rule IDs
-
- SV-61071r1_rule
Checks: C-50631r1_chk
Determine if the FTP server package is installed: # pkg list service/network/ftp If the package is not installed, this check does not apply. # grep DisplayConnect /etc/proftpd.conf If: DisplayConnect /etc/issue does not appear, this is a finding. If /etc/issue does not contain the approved DoD text, this is a finding.
Fix: F-51807r2_fix
The root role is required. The package: pkg:/service/network/ftp must be installed. # pfedit /etc/issue Insert the proper DoD banner message text. The DoD required text is: "You are accessing a U.S. Government (USG) Information System (IS) that is provided for USG-authorized use only. By using this IS (which includes any device attached to this IS), you consent to the following conditions: -The USG routinely intercepts and monitors communications on this IS for purposes including, but not limited to, penetration testing, COMSEC monitoring, network operations and defense, personnel misconduct (PM), law enforcement (LE), and counterintelligence (CI) investigations. -At any time, the USG may inspect and seize data stored on this IS. -Communications using, or data stored on, this IS are not private, are subject to routine monitoring, interception, and search, and may be disclosed or used for any USG-authorized purpose. -This IS includes security measures (e.g., authentication and access controls) to protect USG interests -- not for your personal benefit or privacy. -Notwithstanding the above, using this IS does not constitute consent to PM, LE or CI investigative searching or monitoring of the content of privileged communications, or work product, related to personal representation or services by attorneys, psychotherapists, or clergy, and their assistants. Such communications and work product are private and confidential. See User Agreement for details." # echo "DisplayConnect /etc/issue" >> /etc/proftpd.conf # svcadm restart ftp
- RMF Control
- CM-6
- Severity
- L
- CCI
- CCI-000366
- Version
- SOL-11.1-050100
- Vuln IDs
-
- V-48201
- Rule IDs
-
- SV-61073r1_rule
Checks: C-50635r1_chk
Determine if TCP reverse IP source routing is disabled. # ipadm show-prop -p _rev_src_routes -co current tcp If the output of this command is not "0", this is a finding.
Fix: F-51811r1_fix
The Network Management profile is required. Disable reverse source routing. # pfexec ipadm set-prop -p _rev_src_routes=0 tcp
- RMF Control
- AC-8
- Severity
- L
- CCI
- CCI-000048
- Version
- SOL-11.1-050410
- Vuln IDs
-
- V-48203
- Rule IDs
-
- SV-61075r1_rule
Checks: C-50633r1_chk
This item does not apply if a graphic login is not configured. Log in to the Gnome Graphical interface. If the approved banner message does not appear, this is a finding. # cat /etc/issue # grep /etc/gdm/Init/Default zenity If /etc/issue does not contain that DoD-approved banner message or /etc/gdm/Init/Default does not contain the line: /usr/bin/zenity --text-info --width=800 --height=300 \ --title="Security Message" --filename=/etc/issue this is a finding.
Fix: F-51809r1_fix
The root role is required. If the system does not use XWindows, this is not applicable. # pfedit /etc/issue Insert the proper DoD banner message text. The DoD required text is: "You are accessing a U.S. Government (USG) Information System (IS) that is provided for USG-authorized use only. By using this IS (which includes any device attached to this IS), you consent to the following conditions: -The USG routinely intercepts and monitors communications on this IS for purposes including, but not limited to, penetration testing, COMSEC monitoring, network operations and defense, personnel misconduct (PM), law enforcement (LE), and counterintelligence (CI) investigations. -At any time, the USG may inspect and seize data stored on this IS. -Communications using, or data stored on, this IS are not private, are subject to routine monitoring, interception, and search, and may be disclosed or used for any USG-authorized purpose. -This IS includes security measures (e.g., authentication and access controls) to protect USG interests -- not for your personal benefit or privacy. -Notwithstanding the above, using this IS does not constitute consent to PM, LE or CI investigative searching or monitoring of the content of privileged communications, or work product, related to personal representation or services by attorneys, psychotherapists, or clergy, and their assistants. Such communications and work product are private and confidential. See User Agreement for details." # pfedit /etc/gdm/Init/Default Add the following content before the "exit 0" line of the file. /usr/bin/zenity --text-info --width=800 --height=300 \ --title="Security Message" --filename=/etc/issue
- RMF Control
- AC-8
- Severity
- L
- CCI
- CCI-000048
- Version
- SOL-11.1-050390
- Vuln IDs
-
- V-48205
- Rule IDs
-
- SV-61077r1_rule
Checks: C-50639r1_chk
Check SSH configuration for banner message: # grep "^Banner" /etc/ssh/sshd_config If the output is not: Banner /etc/issue and /etc/issue does not contain the approved banner text, this is a finding.
Fix: F-51815r1_fix
The root role is required. Edit the SSH configuration file. # pfedit /etc/ssh/sshd_config Locate the file containing: Banner Change the line to read: Banner /etc/issue Edit the /etc/issue file # pfedit /etc/issue The DoD required text is: "You are accessing a U.S. Government (USG) Information System (IS) that is provided for USG-authorized use only. By using this IS (which includes any device attached to this IS), you consent to the following conditions: -The USG routinely intercepts and monitors communications on this IS for purposes including, but not limited to, penetration testing, COMSEC monitoring, network operations and defense, personnel misconduct (PM), law enforcement (LE), and counterintelligence (CI) investigations. -At any time, the USG may inspect and seize data stored on this IS. -Communications using, or data stored on, this IS are not private, are subject to routine monitoring, interception, and search, and may be disclosed or used for any USG-authorized purpose. -This IS includes security measures (e.g., authentication and access controls) to protect USG interests -- not for your personal benefit or privacy. -Notwithstanding the above, using this IS does not constitute consent to PM, LE or CI investigative searching or monitoring of the content of privileged communications, or work product, related to personal representation or services by attorneys, psychotherapists, or clergy, and their assistants. Such communications and work product are private and confidential. See User Agreement for details." Restart the SSH service # svcadm restart svc:/network/ssh
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SOL-11.1-050110
- Vuln IDs
-
- V-48207
- Rule IDs
-
- SV-61079r1_rule
Checks: C-50637r1_chk
Determine if the number of half open TCP connections is set to 4096. # ipadm show-prop -p _conn_req_max_q0 -co current tcp If the value of "4096" is not returned, this is a finding.
Fix: F-51813r1_fix
The Network Management profile is required Configure maximum TCP connections for IPv4 and IPv6. # pfexec ipadm set-prop -p _conn_req_max_q0=4096 tcp
- RMF Control
- AC-8
- Severity
- L
- CCI
- CCI-000048
- Version
- SOL-11.1-050380
- Vuln IDs
-
- V-48209
- Rule IDs
-
- SV-61081r1_rule
Checks: C-50641r1_chk
Review the contents of these two files and check that the proper DoD banner message is configured. # cat /etc/motd # cat /etc/issue If the DoD-approved banner text is not in the files, this is a finding.
Fix: F-51817r1_fix
The root role is required. Edit the contents of these two files and ensure that the proper DoD banner message is viewable. # pfedit /etc/motd # pfedit /etc/issue The DoD required text is: "You are accessing a U.S. Government (USG) Information System (IS) that is provided for USG-authorized use only. By using this IS (which includes any device attached to this IS), you consent to the following conditions: -The USG routinely intercepts and monitors communications on this IS for purposes including, but not limited to, penetration testing, COMSEC monitoring, network operations and defense, personnel misconduct (PM), law enforcement (LE), and counterintelligence (CI) investigations. -At any time, the USG may inspect and seize data stored on this IS. -Communications using, or data stored on, this IS are not private, are subject to routine monitoring, interception, and search, and may be disclosed or used for any USG-authorized purpose. -This IS includes security measures (e.g., authentication and access controls) to protect USG interests -- not for your personal benefit or privacy. -Notwithstanding the above, using this IS does not constitute consent to PM, LE or CI investigative searching or monitoring of the content of privileged communications, or work product, related to personal representation or services by attorneys, psychotherapists, or clergy, and their assistants. Such communications and work product are private and confidential. See User Agreement for details."
- RMF Control
- CM-6
- Severity
- L
- CCI
- CCI-000366
- Version
- SOL-11.1-050120
- Vuln IDs
-
- V-48211
- Rule IDs
-
- SV-61083r1_rule
Checks: C-50643r1_chk
Determine if the maximum number of incoming connections is set to 1024. # ipadm show-prop -p _conn_req_max_q -co current tcp If the value returned is smaller than "1024", this is a finding. In environments where connection numbers are high, such as a busy web server, this value may need to be increased.
Fix: F-51819r1_fix
The Network Management profile is required. Configure maximum number of incoming connections. # pfexec ipadm set-prop -p _conn_req_max_q=1024 tcp
- RMF Control
- CM-6
- Severity
- L
- CCI
- CCI-000366
- Version
- SOL-11.1-050370
- Vuln IDs
-
- V-48213
- Rule IDs
-
- SV-61085r3_rule
Checks: C-50645r3_chk
The IP Filter Management profile is required. Check the system for an IPF rule blocking outgoing source-routed packets. # ipfstat -o Examine the list for rules such as: block out log quick from any to any with opt lsrr block out log quick from any to any with opt ssrr If the listed rules do not block both lsrr and ssrr options, this is a finding.
Fix: F-51821r3_fix
The root role is required. # pfedit /etc/ipf/ipf.conf Add rules to block outgoing source-routed packets, such as: block out log quick all with opt lsrr block out log quick all with opt ssrr Reload the IPF rules. # ipf -Fa -A -f /etc/ipf/ipf.conf
- RMF Control
- AC-17
- Severity
- M
- CCI
- CCI-000066
- Version
- SOL-11.1-050360
- Vuln IDs
-
- V-48215
- Rule IDs
-
- SV-61087r1_rule
Checks: C-50649r1_chk
The IP Filter Management profile is required. Check that the IP Filter firewall is enabled and configured so that only encrypted SSH sessions are allowed. # svcs ipfilter If ipfilter is not listed with a state of online, this is a finding. The IP Filter Management profile is required. Check that the filters are configured properly. # ipfstat -io If the output of this command does not include these lines: block out log all keep state keep frags pass in log quick proto tcp from any to any port = ssh keep state block in log all block in log from any to 255.255.255.255/32 block in log from any to 127.0.0.1/32 this is a finding. Even if the lines above are included in the output, it is possible that other lines can contradict the firewall settings. Review the firewall rules and ensure that they conform to organizational and mission requirements. If the firewall rules are not configured to organizational standards, this is a finding.
Fix: F-51823r1_fix
The root role is required. Configure and enable the IP Filters policy. # pfedit /etc/ipf/ipf.conf. Add these lines to the file: # Allow SSH (note you cannot restrict to SSHv2 here. This can # only be done in /etc/ssh/sshd_config.) pass in log quick proto tcp from any to any port = 22 keep state # Do not allow all outbound traffic, keep state, and log block out log all keep state keep frags # Block and log everything else that comes in block in log all block in log from any to 255.255.255.255 block in log from any to 127.0.0.1/32 Enable ipfilter. # svcadm enable ipfilter Notify ipfilter to use the new configuration file. # ipf -Fa -f /etc/ipf/ipf.conf Note: This is an extremely strict firewall policy disabling all network traffic except incoming SSH (port 22) connections. Operational requirements may dictate the addition of other protocols such as DNS, NTP, HTTP, and HTTPS to be allowed.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SOL-11.1-050130
- Vuln IDs
-
- V-48217
- Rule IDs
-
- SV-61089r1_rule
Checks: C-50647r1_chk
Determine if routing is disabled. # routeadm -p | egrep "routing |forwarding" | grep enabled If the command output includes "persistent=enabled" or "current=enabled", this is a finding.
Fix: F-51825r1_fix
The Network Management profile is required. Disable routing for IPv4 and IPv6. # pfexec routeadm -d ipv4-forwarding -d ipv4-routing # pfexec routeadm -d ipv6-forwarding -d ipv6-routing To apply these changes to the running system, use the command: # pfexec routeadm -u
- RMF Control
- SC-15
- Severity
- M
- CCI
- CCI-001154
- Version
- SOL-11.1-050350
- Vuln IDs
-
- V-48219
- Rule IDs
-
- SV-61091r1_rule
Checks: C-50651r1_chk
The IP Filter Management profile is required. Check that the IP Filter firewall is enabled and configured so that only encrypted SSH sessions are allowed. # svcs ipfilter If ipfilter is not listed with a state of online, this is a finding. The IP Filter Management profile is required. Check that the filters are configured properly. # ipfstat -io If the output of this command does not include these lines: block out log all keep state keep frags pass in log quick proto tcp from any to any port = ssh keep state block in log all block in log from any to 255.255.255.255/32 block in log from any to 127.0.0.1/32 this is a finding. Even if the lines above are included in the output, it is possible that other lines can contradict the firewall settings. Review the firewall rules and ensure that they conform to organizational and mission requirements. If the firewall rules are not configured to organizational standards, this is a finding.
Fix: F-51827r1_fix
The root role is required. Configure and enable the IP Filters policy. # pfedit /etc/ipf/ipf.conf. Add these lines to the file: # Allow SSH (note you cannot restrict to SSHv2 here. This can # only be done in /etc/ssh/sshd_config.) pass in log quick proto tcp from any to any port = 22 keep state # Do not allow all outbound traffic, keep state, and log block out log all keep state keep frags # Block and log everything else that comes in block in log all block in log from any to 255.255.255.255 block in log from any to 127.0.0.1/32 Enable ipfilter. # svcadm enable ipfilter Notify ipfilter to use the new configuration file. # ipf -Fa -f /etc/ipf/ipf.conf Note: This is an extremely strict firewall policy disabling all network traffic except incoming SSH (port 22) connections. Operational requirements may dictate the addition of other protocols such as DNS, NTP, HTTP, and HTTPS to be allowed.
- RMF Control
- CM-6
- Severity
- L
- CCI
- CCI-000366
- Version
- SOL-11.1-050140
- Vuln IDs
-
- V-48221
- Rule IDs
-
- SV-61093r1_rule
Checks: C-50653r1_chk
Determine if TCP Wrappers is configured. # inetadm -p | grep tcp_wrappers If the output of this command is "FALSE", this is a finding. The above command will check whether TCP Wrappers is enabled for all TCP-based services started by inetd. TCP Wrappers are enabled by default for sendmail and SSH. Individual inetd services may still be configured to use TCP Wrappers even if the global parameter (above) is set to "FALSE". To check the status of individual inetd services, use the command: # for svc in `inetadm | awk '/svc:\// { print $NF }'`; do val=`inetadm -l ${svc} | grep -c tcp_wrappers=TRUE` if [ ${val} -eq 1 ]; then echo "TCP Wrappers enabled for ${svc}" fi done If the required services are not configured to use TCP Wrappers, this is finding. # ls /etc/hosts.deny # ls /etc/hosts.allow If these files are not found, this is a finding.
Fix: F-51829r2_fix
The root role is required. Configure allowed and denied hosts per organizational policy. 1. Create and customize the policy in /etc/hosts.allow: # echo "ALL: [net]/[mask] , [net]/[mask], ..." > /etc/hosts.allow where each [net>/[mask> combination (for example, the Class C address block "192.168.1.0/255.255.255.0") can represent one network block in use by the organization that requires access to this system. 2. Create a default deny policy in /etc/hosts.deny: # echo "ALL: ALL" >/etc/hosts.deny 3. Enable TCP Wrappers for all services started by inetd: # inetadm -M tcp_wrappers=TRUE
- RMF Control
- AC-17
- Severity
- M
- CCI
- CCI-001453
- Version
- SOL-11.1-050330
- Vuln IDs
-
- V-48223
- Rule IDs
-
- SV-61095r1_rule
Checks: C-50655r1_chk
The IP Filter Management profile is required. Check that the IP Filter firewall is enabled and configured so that only encrypted SSH sessions are allowed. # svcs ipfilter If ipfilter is not listed with a state of online, this is a finding. The IP Filter Management profile is required. Check that the filters are configured properly. # ipfstat -io If the output of this command does not include these lines: block out log all keep state keep frags pass in log quick proto tcp from any to any port = ssh keep state block in log all block in log from any to 255.255.255.255/32 block in log from any to 127.0.0.1/32 this is a finding. Even if the lines above are included in the output, it is possible that other lines can contradict the firewall settings. Review the firewall rules and ensure that they conform to organizational and mission requirements. If the firewall rules are not configured to organizational standards, this is a finding.
Fix: F-51831r1_fix
The root role is required. Configure and enable the IP Filters policy. # pfedit /etc/ipf/ipf.conf. Add these lines to the file: # Allow SSH (note you cannot restrict to SSHv2 here. This can # only be done in /etc/ssh/sshd_config.) pass in log quick proto tcp from any to any port = 22 keep state # Do not allow all outbound traffic, keep state, and log block out log all keep state keep frags # Block and log everything else that comes in block in log all block in log from any to 255.255.255.255 block in log from any to 127.0.0.1/32 Enable ipfilter. # svcadm enable ipfilter Notify ipfilter to use the new configuration file. # ipf -Fa -f /etc/ipf/ipf.conf Note: This is an extremely strict firewall policy disabling all network traffic except incoming SSH (port 22) connections. Operational requirements may dictate the addition of other protocols such as DNS, NTP, HTTP, and HTTPS to be allowed.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000382
- Version
- SOL-11.1-050150
- Vuln IDs
-
- V-48225
- Rule IDs
-
- SV-61097r1_rule
Checks: C-50657r1_chk
The IP Filter Management profile is required. Check that the IP Filter firewall is enabled and configured so that only encrypted SSH sessions are allowed. # svcs ipfilter If ipfilter is not listed with a state of online, this is a finding. The IP Filter Management profile is required. Check that the filters are configured properly. # ipfstat -io If the output of this command does not include these lines: block out log all keep state keep frags pass in log quick proto tcp from any to any port = ssh keep state block in log all block in log from any to 255.255.255.255/32 block in log from any to 127.0.0.1/32 this is a finding. Even if the lines above are included in the output, it is possible that other lines can contradict the firewall settings. Review the firewall rules and ensure that they conform to organizational and mission requirements. If the firewall rules are not configured to organizational standards, this is a finding.
Fix: F-51833r1_fix
The root role is required. Configure and enable the IP Filters policy. # pfedit /etc/ipf/ipf.conf. Add these lines to the file: # Allow SSH (note you cannot restrict to SSHv2 here. This can # only be done in /etc/ssh/sshd_config.) pass in log quick proto tcp from any to any port = 22 keep state # Do not allow all outbound traffic, keep state, and log block out log all keep state keep frags # Block and log everything else that comes in block in log all block in log from any to 255.255.255.255 block in log from any to 127.0.0.1/32 Enable ipfilter. # svcadm enable ipfilter Notify ipfilter to use the new configuration file. # ipf -Fa -f /etc/ipf/ipf.conf Note: This is an extremely strict firewall policy disabling all network traffic except incoming SSH (port 22) connections. Operational requirements may dictate the addition of other protocols such as DNS, NTP, HTTP, and HTTPS to be allowed.
- RMF Control
- AC-17
- Severity
- M
- CCI
- CCI-001436
- Version
- SOL-11.1-050320
- Vuln IDs
-
- V-48227
- Rule IDs
-
- SV-61099r1_rule
Checks: C-50659r1_chk
The IP Filter Management profile is required. Check that the IP Filter firewall is enabled and configured so that only encrypted SSH sessions are allowed. # svcs ipfilter If ipfilter is not listed with a state of online, this is a finding. The IP Filter Management profile is required. Check that the filters are configured properly. # ipfstat -io If the output of this command does not include these lines: block out log all keep state keep frags pass in log quick proto tcp from any to any port = ssh keep state block in log all block in log from any to 255.255.255.255/32 block in log from any to 127.0.0.1/32 this is a finding. Even if the lines above are included in the output, it is possible that other lines can contradict the firewall settings. Review the firewall rules and ensure that they conform to organizational and mission requirements. If the firewall rules are not configured to organizational standards, this is a finding.
Fix: F-51835r1_fix
The root role is required. Configure and enable the IP Filters policy. # pfedit /etc/ipf/ipf.conf. Add these lines to the file: # Allow SSH (note you cannot restrict to SSHv2 here. This can # only be done in /etc/ssh/sshd_config.) pass in log quick proto tcp from any to any port = 22 keep state # Do not allow all outbound traffic, keep state, and log block out log all keep state keep frags # Block and log everything else that comes in block in log all block in log from any to 255.255.255.255 block in log from any to 127.0.0.1/32 Enable ipfilter. # svcadm enable ipfilter Notify ipfilter to use the new configuration file. # ipf -Fa -f /etc/ipf/ipf.conf Note: This is an extremely strict firewall policy disabling all network traffic except incoming SSH (port 22) connections. Operational requirements may dictate the addition of other protocols such as DNS, NTP, HTTP, and HTTPS to be allowed.
- RMF Control
- SC-7
- Severity
- M
- CCI
- CCI-001118
- Version
- SOL-11.1-050290
- Vuln IDs
-
- V-48229
- Rule IDs
-
- SV-61101r1_rule
Checks: C-50661r1_chk
The IP Filter Management profile is required. Check that the IP Filter firewall is enabled and configured so that only encrypted SSH sessions are allowed. # svcs ipfilter If ipfilter is not listed with a state of online, this is a finding. The IP Filter Management profile is required. Check that the filters are configured properly. # ipfstat -io If the output of this command does not include these lines: block out log all keep state keep frags pass in log quick proto tcp from any to any port = ssh keep state block in log all block in log from any to 255.255.255.255/32 block in log from any to 127.0.0.1/32 this is a finding. Even if the lines above are included in the output, it is possible that other lines can contradict the firewall settings. Review the firewall rules and ensure that they conform to organizational and mission requirements. If the firewall rules are not configured to organizational standards, this is a finding.
Fix: F-51837r1_fix
The root role is required. Configure and enable the IP Filters policy. # pfedit /etc/ipf/ipf.conf. Add these lines to the file: # Allow SSH (note you cannot restrict to SSHv2 here. This can # only be done in /etc/ssh/sshd_config.) pass in log quick proto tcp from any to any port = 22 keep state # Do not allow all outbound traffic, keep state, and log block out log all keep state keep frags # Block and log everything else that comes in block in log all block in log from any to 255.255.255.255 block in log from any to 127.0.0.1/32 Enable ipfilter. # svcadm enable ipfilter Notify ipfilter to use the new configuration file. # ipf -Fa -f /etc/ipf/ipf.conf Note: This is an extremely strict firewall policy disabling all network traffic except incoming SSH (port 22) connections. Operational requirements may dictate the addition of other protocols such as DNS, NTP, HTTP, and HTTPS to be allowed.
- RMF Control
- IA-2
- Severity
- M
- CCI
- CCI-000774
- Version
- SOL-11.1-050160
- Vuln IDs
-
- V-48231
- Rule IDs
-
- SV-61103r1_rule
Checks: C-50663r1_chk
The IP Filter Management profile is required. Check that the IP Filter firewall is enabled and configured so that only encrypted SSH sessions are allowed. # svcs ipfilter If ipfilter is not listed with a state of online, this is a finding. The IP Filter Management profile is required. Check that the filters are configured properly. # ipfstat -io If the output of this command does not include these lines: block out log all keep state keep frags pass in log quick proto tcp from any to any port = ssh keep state block in log all block in log from any to 255.255.255.255/32 block in log from any to 127.0.0.1/32 this is a finding. Even if the lines above are included in the output, it is possible that other lines can contradict the firewall settings. Review the firewall rules and ensure that they conform to organizational and mission requirements. If the firewall rules are not configured to organizational standards, this is a finding.
Fix: F-51839r1_fix
The root role is required. Configure and enable the IP Filters policy. # pfedit /etc/ipf/ipf.conf. Add these lines to the file: # Allow SSH (note you cannot restrict to SSHv2 here. This can # only be done in /etc/ssh/sshd_config.) pass in log quick proto tcp from any to any port = 22 keep state # Do not allow all outbound traffic, keep state, and log block out log all keep state keep frags # Block and log everything else that comes in block in log all block in log from any to 255.255.255.255 block in log from any to 127.0.0.1/32 Enable ipfilter. # svcadm enable ipfilter Notify ipfilter to use the new configuration file. # ipf -Fa -f /etc/ipf/ipf.conf Note: This is an extremely strict firewall policy disabling all network traffic except incoming SSH (port 22) connections. Operational requirements may dictate the addition of other protocols such as DNS, NTP, HTTP, and HTTPS to be allowed.
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-000197
- Version
- SOL-11.1-050270
- Vuln IDs
-
- V-48233
- Rule IDs
-
- SV-61105r1_rule
Checks: C-50665r1_chk
The IP Filter Management profile is required. Check that the IP Filter firewall is enabled and configured so that only encrypted SSH sessions are allowed. # svcs ipfilter If ipfilter is not listed with a state of online, this is a finding. The IP Filter Management profile is required. Check that the filters are configured properly. # ipfstat -io If the output of this command does not include these lines: block out log all keep state keep frags pass in log quick proto tcp from any to any port = ssh keep state block in log all block in log from any to 255.255.255.255/32 block in log from any to 127.0.0.1/32 this is a finding. Even if the lines above are included in the output, it is possible that other lines can contradict the firewall settings. Review the firewall rules and ensure that they conform to organizational and mission requirements. If the firewall rules are not configured to organizational standards, this is a finding.
Fix: F-51841r1_fix
The root role is required. Configure and enable the IP Filters policy. # pfedit /etc/ipf/ipf.conf. Add these lines to the file: # Allow SSH (note you cannot restrict to SSHv2 here. This can # only be done in /etc/ssh/sshd_config.) pass in log quick proto tcp from any to any port = 22 keep state # Do not allow all outbound traffic, keep state, and log block out log all keep state keep frags # Block and log everything else that comes in block in log all block in log from any to 255.255.255.255 block in log from any to 127.0.0.1/32 Enable ipfilter. # svcadm enable ipfilter Notify ipfilter to use the new configuration file. # ipf -Fa -f /etc/ipf/ipf.conf Note: This is an extremely strict firewall policy disabling all network traffic except incoming SSH (port 22) connections. Operational requirements may dictate the addition of other protocols such as DNS, NTP, HTTP, and HTTPS to be allowed.
- RMF Control
- SC-7
- Severity
- M
- CCI
- CCI-001109
- Version
- SOL-11.1-050240
- Vuln IDs
-
- V-48235
- Rule IDs
-
- SV-61107r1_rule
Checks: C-50667r1_chk
The IP Filter Management profile is required. Check that the IP Filter firewall is enabled and configured so that only encrypted SSH sessions are allowed. # svcs ipfilter If ipfilter is not listed with a state of online, this is a finding. The IP Filter Management profile is required. Check that the filters are configured properly. # ipfstat -io If the output of this command does not include these lines: block out log all keep state keep frags pass in log quick proto tcp from any to any port = ssh keep state block in log all block in log from any to 255.255.255.255/32 block in log from any to 127.0.0.1/32 this is a finding. Even if the lines above are included in the output, it is possible that other lines can contradict the firewall settings. Review the firewall rules and ensure that they conform to organizational and mission requirements. If the firewall rules are not configured to organizational standards, this is a finding.
Fix: F-51843r1_fix
The root role is required. Configure and enable the IP Filters policy. # pfedit /etc/ipf/ipf.conf. Add these lines to the file: # Allow SSH (note you cannot restrict to SSHv2 here. This can # only be done in /etc/ssh/sshd_config.) pass in log quick proto tcp from any to any port = 22 keep state # Do not allow all outbound traffic, keep state, and log block out log all keep state keep frags # Block and log everything else that comes in block in log all block in log from any to 255.255.255.255 block in log from any to 127.0.0.1/32 Enable ipfilter. # svcadm enable ipfilter Notify ipfilter to use the new configuration file. # ipf -Fa -f /etc/ipf/ipf.conf Note: This is an extremely strict firewall policy disabling all network traffic except incoming SSH (port 22) connections. Operational requirements may dictate the addition of other protocols such as DNS, NTP, HTTP, and HTTPS to be allowed.
- RMF Control
- IA-2
- Severity
- M
- CCI
- CCI-000776
- Version
- SOL-11.1-050170
- Vuln IDs
-
- V-48237
- Rule IDs
-
- SV-61109r1_rule
Checks: C-50669r1_chk
The IP Filter Management profile is required. Check that the IP Filter firewall is enabled and configured so that only encrypted SSH sessions are allowed. # svcs ipfilter If ipfilter is not listed with a state of online, this is a finding. The IP Filter Management profile is required. Check that the filters are configured properly. # ipfstat -io If the output of this command does not include these lines: block out log all keep state keep frags pass in log quick proto tcp from any to any port = ssh keep state block in log all block in log from any to 255.255.255.255/32 block in log from any to 127.0.0.1/32 this is a finding. Even if the lines above are included in the output, it is possible that other lines can contradict the firewall settings. Review the firewall rules and ensure that they conform to organizational and mission requirements. If the firewall rules are not configured to organizational standards, this is a finding.
Fix: F-51845r1_fix
The root role is required. Configure and enable the IP Filters policy. # pfedit /etc/ipf/ipf.conf. Add these lines to the file: # Allow SSH (note you cannot restrict to SSHv2 here. This can # only be done in /etc/ssh/sshd_config.) pass in log quick proto tcp from any to any port = 22 keep state # Do not allow all outbound traffic, keep state, and log block out log all keep state keep frags # Block and log everything else that comes in block in log all block in log from any to 255.255.255.255 block in log from any to 127.0.0.1/32 Enable ipfilter. # svcadm enable ipfilter Notify ipfilter to use the new configuration file. # ipf -Fa -f /etc/ipf/ipf.conf Note: This is an extremely strict firewall policy disabling all network traffic except incoming SSH (port 22) connections. Operational requirements may dictate the addition of other protocols such as DNS, NTP, HTTP, and HTTPS to be allowed.
- RMF Control
- MA-4
- Severity
- M
- CCI
- CCI-000877
- Version
- SOL-11.1-050180
- Vuln IDs
-
- V-48239
- Rule IDs
-
- SV-61111r1_rule
Checks: C-50671r1_chk
The IP Filter Management profile is required. Check that the IP Filter firewall is enabled and configured so that only encrypted SSH sessions are allowed. # svcs ipfilter If ipfilter is not listed with a state of online, this is a finding. The IP Filter Management profile is required. Check that the filters are configured properly. # ipfstat -io If the output of this command does not include these lines: block out log all keep state keep frags pass in log quick proto tcp from any to any port = ssh keep state block in log all block in log from any to 255.255.255.255/32 block in log from any to 127.0.0.1/32 this is a finding. Even if the lines above are included in the output, it is possible that other lines can contradict the firewall settings. Review the firewall rules and ensure that they conform to organizational and mission requirements. If the firewall rules are not configured to organizational standards, this is a finding.
Fix: F-51847r1_fix
The root role is required. Configure and enable the IP Filters policy. # pfedit /etc/ipf/ipf.conf. Add these lines to the file: # Allow SSH (note you cannot restrict to SSHv2 here. This can # only be done in /etc/ssh/sshd_config.) pass in log quick proto tcp from any to any port = 22 keep state # Do not allow all outbound traffic, keep state, and log block out log all keep state keep frags # Block and log everything else that comes in block in log all block in log from any to 255.255.255.255 block in log from any to 127.0.0.1/32 Enable ipfilter. # svcadm enable ipfilter Notify ipfilter to use the new configuration file. # ipf -Fa -f /etc/ipf/ipf.conf Note: This is an extremely strict firewall policy disabling all network traffic except incoming SSH (port 22) connections. Operational requirements may dictate the addition of other protocols such as DNS, NTP, HTTP, and HTTPS to be allowed.
- RMF Control
- MA-4
- Severity
- M
- CCI
- CCI-000888
- Version
- SOL-11.1-050190
- Vuln IDs
-
- V-48241
- Rule IDs
-
- SV-61113r1_rule
Checks: C-50673r1_chk
The IP Filter Management profile is required. Check that the IP Filter firewall is enabled and configured so that only encrypted SSH sessions are allowed. # svcs ipfilter If ipfilter is not listed with a state of online, this is a finding. The IP Filter Management profile is required. Check that the filters are configured properly. # ipfstat -io If the output of this command does not include these lines: block out log all keep state keep frags pass in log quick proto tcp from any to any port = ssh keep state block in log all block in log from any to 255.255.255.255/32 block in log from any to 127.0.0.1/32 this is a finding. Even if the lines above are included in the output, it is possible that other lines can contradict the firewall settings. Review the firewall rules and ensure that they conform to organizational and mission requirements. If the firewall rules are not configured to organizational standards, this is a finding.
Fix: F-51849r1_fix
The root role is required. Configure and enable the IP Filters policy. # pfedit /etc/ipf/ipf.conf. Add these lines to the file: # Allow SSH (note you cannot restrict to SSHv2 here. This can # only be done in /etc/ssh/sshd_config.) pass in log quick proto tcp from any to any port = 22 keep state # Do not allow all outbound traffic, keep state, and log block out log all keep state keep frags # Block and log everything else that comes in block in log all block in log from any to 255.255.255.255 block in log from any to 127.0.0.1/32 Enable ipfilter. # svcadm enable ipfilter Notify ipfilter to use the new configuration file. # ipf -Fa -f /etc/ipf/ipf.conf Note: This is an extremely strict firewall policy disabling all network traffic except incoming SSH (port 22) connections. Operational requirements may dictate the addition of other protocols such as DNS, NTP, HTTP, and HTTPS to be allowed.
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-000196
- Version
- SOL-11.1-040130
- Vuln IDs
-
- V-48243
- Rule IDs
-
- SV-61115r3_rule
Checks: C-50675r3_chk
Determine which cryptographic algorithms are configured. # grep ^CRYPT /etc/security/policy.conf If the command output does not include the lines: CRYPT_DEFAULT=6 CRYPT_ALGORITHMS_ALLOW=5,6 this is a finding.
Fix: F-51851r2_fix
The root role is required. Configure the system to disallow the use of UNIX encryption and enable SHA256 as the default encryption hash. # pfedit /etc/security/policy.conf Check that the lines: CRYPT_DEFAULT=6 CRYPT_ALOGRITHMS_ALLOW=5,6 exist and are not commented out.
- RMF Control
- AC-7
- Severity
- M
- CCI
- CCI-000044
- Version
- SOL-11.1-040140
- Vuln IDs
-
- V-48245
- Rule IDs
-
- SV-61117r1_rule
Checks: C-50677r1_chk
Verify RETRIES is set in the login file. # grep ^RETRIES /etc/default/login If the output is not RETRIES=3 or fewer, this is a finding. Verify the account locks after invalid login attempts. # grep ^LOCK_AFTER_RETRIES /etc/security/policy.conf If the output is not LOCK_AFTER_RETRIES=YES, this is a finding. For each user in the system, use the command: # userattr lock_after_retries [username] to determine if the user overrides the system value. If the output of this command is "no", this is a finding.
Fix: F-51853r1_fix
The root role is required. # pfedit /etc/default/login Change the line: #RETRIES=5 to read RETRIES=3 pfedit /etc/security/policy.conf Change the line containing #LOCK_AFTER_RETRIES to read: LOCK_AFTER_RETRIES=YES If a user has lock_after_retries set to "no", update the user's attributes using the command: # usermod -K lock_after_retries=yes [username]
- RMF Control
- AU-4
- Severity
- H
- CCI
- CCI-000138
- Version
- SOL-11.1-010410
- Vuln IDs
-
- V-49621
- Rule IDs
-
- SV-62545r1_rule
Checks: C-51543r1_chk
The Audit Configuration profile is required. This check applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this check applies. Check the status of the audit system. It must be auditing. # pfexec auditconfig -getplugin If the output of this command does not contain: p_fsize=4M this is a finding.
Fix: F-53123r1_fix
The Audit Control profile is required. This action applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global", this action applies. Set the size of a binary audit file to a specific size. The size is specified in megabytes. # pfexec auditconfig -setplugin audit_binfile p_fsize=4M Restart the audit system. # pfexec audit -s
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SOL-11.1-090115
- Vuln IDs
-
- V-49625
- Rule IDs
-
- SV-62549r1_rule
Checks: C-51545r1_chk
The operator will ensure that a DoD approved PKI system is installed, configured, and properly operating. Ask the operator to document the PKI software installation and configuration. If the operator is not able to provide a documented configuration for an installed PKI system or if the PKI system is not properly configured, maintained, or used, this is a finding.
Fix: F-53127r1_fix
The operator will ensure that a DoD approved PKI software is installed and operating continuously.
- RMF Control
- AC-19
- Severity
- M
- CCI
- CCI-000085
- Version
- SOL-11.1-120410
- Vuln IDs
-
- V-49635
- Rule IDs
-
- SV-62559r1_rule
Checks: C-51547r1_chk
This check applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global" this check applies. Determine if USB mass storage devices are locked out by the kernel. # grep "exclude: scsa2usb" /etc/system If the output of this command is not: exclude: scsa2usb this is a finding.
Fix: F-53137r1_fix
The root role is required. This check applies to the global zone only. Determine the zone that you are currently securing. # zonename If the command output is "global" this check applies. Modify the /etc/system file. # pfedit /etc/system Add a line containing: exclude: scsa2usb Note that the global zone will need to be rebooted for this change to take effect.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SOL-11.1-020300
- Vuln IDs
-
- V-59827
- Rule IDs
-
- SV-74257r1_rule
Checks: C-60583r1_chk
Check run control script modes. # ls -lL /etc/rc* /etc/init.d /lib/svc/method If any run control script has a mode more permissive than 0755, this is a finding.
Fix: F-65237r1_fix
Ensure all system startup files have mode 0755 or less permissive. Examine the rc files, and all files in the rc1.d (rc2.d, and so on) directories, and in the /etc/init.d and /lib/svc/method directories to ensure they are not world writable. If they are world writable, use the chmod command to correct the vulnerability and to research why. Procedure: # chmod go-w <startupfile>
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SOL-11.1-020310
- Vuln IDs
-
- V-59829
- Rule IDs
-
- SV-74259r1_rule
Checks: C-60585r1_chk
Verify run control scripts have no extended ACLs. # ls -lL /etc/rc* /etc/init.d If the permissions include a "+", the file has an extended ACL and this is a finding.
Fix: F-65239r1_fix
Remove the extended ACL from the file. # chmod A- [run control script with extended ACL]
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SOL-11.1-020320
- Vuln IDs
-
- V-59831
- Rule IDs
-
- SV-74261r3_rule
Checks: C-60587r3_chk
Verify run control scripts' executable search paths. Procedure: # find /etc/rc* /etc/init.d /lib/svc/method -type f -print | xargs grep -i PATH This variable is formatted as a colon-separated list of directories. If there is an empty entry, such as a leading or trailing colon or two consecutive colons, this is a finding. If an entry begins with a character other than a slash (/), or has not been documented with the ISSO, this is a finding.
Fix: F-65241r2_fix
Edit the run control script and remove the relative path entries from the executable search path variable that have not been documented with the ISSO. Edit the run control script and remove any empty path entries from the file.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SOL-11.1-020330
- Vuln IDs
-
- V-59833
- Rule IDs
-
- SV-74263r2_rule
Checks: C-60589r2_chk
Verify run control scripts' library search paths. # find /etc/rc* /etc/init.d -type f -print | xargs grep LD_LIBRARY_PATH This variable is formatted as a colon-separated list of directories. If there is an empty entry, such as a leading or trailing colon, or two consecutive colons, this is a finding. If an entry begins with a character other than a slash (/), or has not been documented with the ISSO, this is a finding.
Fix: F-65243r2_fix
Edit the run control script and remove the relative path entries from the library search path variables that have not been documented with the ISSO. Edit the run control script and remove any empty path entries from the file.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SOL-11.1-020340
- Vuln IDs
-
- V-59835
- Rule IDs
-
- SV-74265r2_rule
Checks: C-60591r2_chk
Verify run control scripts' library preload list. Procedure: # find /etc/rc* /etc/init.d -type f -print | xargs grep LD_PRELOAD This variable is formatted as a colon-separated list of paths. If there is an empty entry, such as a leading or trailing colon, or two consecutive colons, this is a finding. If an entry begins with a character other than a slash (/), or has not been documented with the ISSO, this is a finding.
Fix: F-65245r2_fix
Edit the run control script and remove the relative path entries from the library preload variables that have not been documented with the ISSO. Edit the run control script and remove any empty path entries from the file.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SOL-11.1-020350
- Vuln IDs
-
- V-59837
- Rule IDs
-
- SV-74267r3_rule
Checks: C-60593r3_chk
Check the permissions on the files or scripts executed from system startup scripts to see if they are world writable. Create a list of all potential run command level scripts. # ls -l /etc/init.d/* /etc/rc* | tr '\011' ' ' | tr -s ' ' | cut -f 9,9 -d " " Create a list of world writable files. # find / -perm -002 -type f >> WorldWritableFileList Determine if any of the world writeable files in "WorldWritableFileList" are called from the run command level scripts. Note: Depending upon the number of scripts vs. world writable files, it may be easier to inspect the scripts manually. # more `ls -l /etc/init.d/* /etc/rc* | tr '\011' ' ' | tr -s ' ' | cut -f 9,9 -d " "` If any system startup script executes any file or script that is world writable, this is a finding.
Fix: F-65247r1_fix
Remove the world writable permission from programs or scripts executed by run control scripts. Procedure: # chmod o-w <program or script executed from run control script>
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SOL-11.1-020360
- Vuln IDs
-
- V-59839
- Rule IDs
-
- SV-74269r1_rule
Checks: C-60595r1_chk
Check run control scripts' ownership. # ls -lL /etc/rc* /etc/init.d If any run control script is not owned by root, this is a finding.
Fix: F-65249r1_fix
Change the ownership of the run control script(s) with incorrect ownership. # chown root <run control script>
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SOL-11.1-020370
- Vuln IDs
-
- V-59841
- Rule IDs
-
- SV-74271r1_rule
Checks: C-60597r1_chk
Check run control scripts' group ownership. Procedure: # ls -lL /etc/rc* /etc/init.d If any run control script is not group-owned by root, sys, or bin, this is a finding.
Fix: F-65251r1_fix
Change the group ownership of the run control script(s) with incorrect group ownership. Procedure: # chgrp root <run control script>
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- SOL-11.1-020380
- Vuln IDs
-
- V-59843
- Rule IDs
-
- SV-74273r1_rule
Checks: C-60599r1_chk
Determine the programs executed by system start-up files. Determine the ownership of the executed programs. # cat /etc/rc* /etc/init.d/* | more Check the ownership of every program executed by the system start-up files. # ls -l <executed program> If any executed program is not owned by root, sys, bin, or in rare cases, an application account, this is a finding.
Fix: F-65253r1_fix
Change the ownership of the file executed from system startup scripts to root, bin, or sys. # chown root <executed file>
- RMF Control
- CM-2
- Severity
- M
- CCI
- CCI-000297
- Version
- SOL-11.1-020500
- Vuln IDs
-
- V-61003
- Rule IDs
-
- SV-75471r1_rule
Checks: C-61915r1_chk
If X Windows is not used on the system, this is not applicable. Check for .Xauthority files being utilized by looking for such files in the home directory of a user that uses X. Procedure: # cd ~someuser # ls -la .Xauthority If the .Xauthority file does not exist, ask the SA if the user is using X Windows. If the user is utilizing X Windows and the .Xauthority file does not exist, this is a finding.
Fix: F-66735r1_fix
Ensure the X Windows host is configured to write .Xauthority files into user home directories. Edit the Xaccess file. Ensure the line that writes the .Xauthority file is uncommented.
- RMF Control
- AC-6
- Severity
- M
- CCI
- CCI-000225
- Version
- SOL-11.1-020510
- Vuln IDs
-
- V-61005
- Rule IDs
-
- SV-75473r1_rule
Checks: C-61917r1_chk
If X Windows is not used on the system, this is not applicable. Check the file permissions for the .Xauthority files in the home directories of users of X. Procedure: # cd ~<X user> # ls -lL .Xauthority If the file mode is more permissive than 0600, this is finding.
Fix: F-66737r1_fix
Change the mode of the .Xauthority files. Procedure: # chmod 0600 .Xauthority
- RMF Control
- AC-6
- Severity
- M
- CCI
- CCI-000225
- Version
- SOL-11.1-020520
- Vuln IDs
-
- V-61023
- Rule IDs
-
- SV-75491r1_rule
Checks: C-61935r1_chk
If X Windows is not used on the system, this is not applicable. Check the file permissions for the .Xauthority files. # ls -lL .Xauthority If the permissions include a "+", the file has an extended ACL and this is a finding.
Fix: F-66755r1_fix
Remove the extended ACL from the file. # chmod A- .Xauthority
- RMF Control
- AC-6
- Severity
- H
- CCI
- CCI-000225
- Version
- SOL-11.1-020530
- Vuln IDs
-
- V-61025
- Rule IDs
-
- SV-75493r1_rule
Checks: C-61937r1_chk
If X Windows is not used on the system, this is not applicable. Check the output of the xhost command from an X terminal. Procedure: $ xhost If the output reports access control is enabled (and possibly lists the hosts that can receive X Window logins), this is not a finding. If the xhost command returns a line indicating access control is disabled, this is a finding. NOTE: It may be necessary to define the display if the command reports it cannot open the display. Procedure: $ DISPLAY=MachineName:0.0; export DISPLAY MachineName may be replaced with an Internet Protocol Address. Repeat the check procedure after setting the display.
Fix: F-66757r1_fix
If using an xhost-type authentication the xhost - command can be used to remove current trusted hosts and then selectively allow only trusted hosts to connect with xhost + commands. A cryptographically secure authentication, such as provided by the xauth program, is always preferred. Refer to your X11 server's documentation for further security information.
- RMF Control
- CM-2
- Severity
- M
- CCI
- CCI-000297
- Version
- SOL-11.1-020540
- Vuln IDs
-
- V-61027
- Rule IDs
-
- SV-75495r1_rule
Checks: C-61939r1_chk
If X Windows is not used on the system, this is not applicable. Determine if the X server is running. Procedure: # ps -ef |grep X Determine if xauth is being used. Procedure: # xauth xauth> list If the above command sequence does not show any host other than the localhost, then xauth is not being used. Search the system for an X*.hosts files, where * is a display number that may be used to limit X window connections. If no files are found, X*.hosts files are not being used. If the X*.hosts files contain any unauthorized hosts, this is a finding. If both xauth and X*.hosts files are not being used, this is a finding.
Fix: F-66759r1_fix
Create an X*.hosts file, where * is a display number that may be used to limit X window connections. Add the list of authorized X clients to the file.
- RMF Control
- AC-6
- Severity
- M
- CCI
- CCI-000225
- Version
- SOL-11.1-020550
- Vuln IDs
-
- V-61029
- Rule IDs
-
- SV-75497r1_rule
Checks: C-61943r1_chk
If X Windows is not used on the system, this is not applicable. Check the X Window system access is limited to authorized clients. Procedure: # xauth xauth> list Ask the SA if the clients listed are authorized. If any are not, this is a finding.
Fix: F-66761r1_fix
Remove unauthorized clients from the xauth configuration. # xauth remove <display name>
- RMF Control
- AC-17
- Severity
- M
- CCI
- CCI-001436
- Version
- SOL-11.1-020560
- Vuln IDs
-
- V-61031
- Rule IDs
-
- SV-75499r1_rule
Checks: C-61947r1_chk
Determine if the X Window system is running. Procedure: # ps -ef |grep X Ask the SA if the X Window system is an operational requirement. If it is not, this is a finding.
Fix: F-66763r1_fix
Disable the X Windows server on the system.
- RMF Control
- AC-18
- Severity
- M
- CCI
- CCI-001443
- Version
- SOL-11.1-050480
- Vuln IDs
-
- V-72827
- Rule IDs
-
- SV-87479r2_rule
Checks: C-72959r1_chk
This is N/A for systems that do not have wireless network adapters. Verify that there are no wireless interfaces configured on the system: # ifconfig -a eth0 Link encap:Ethernet HWaddr b8:ac:6f:65:31:e5 inet addr:192.168.2.100 Bcast:192.168.2.255 Mask:255.255.255.0 inet6 addr: fe80::baac:6fff:fe65:31e5/64 Scope:Link UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1 RX packets:2697529 errors:0 dropped:0 overruns:0 frame:0 TX packets:2630541 errors:0 dropped:0 overruns:0 carrier:0 collisions:0 txqueuelen:1000 RX bytes:2159382827 (2.0 GiB) TX bytes:1389552776 (1.2 GiB) Interrupt:17 lo Link encap:Local Loopback inet addr:127.0.0.1 Mask:255.0.0.0 inet6 addr: ::1/128 Scope:Host UP LOOPBACK RUNNING MTU:16436 Metric:1 RX packets:2849 errors:0 dropped:0 overruns:0 frame:0 TX packets:2849 errors:0 dropped:0 overruns:0 carrier:0 collisions:0 txqueuelen:0 RX bytes:2778290 (2.6 MiB) TX bytes:2778290 (2.6 MiB) If a wireless interface is configured, it must be documented and approved by the local Authorizing Official. If a wireless interface is configured and has not been documented and approved, this is a finding.
Fix: F-79265r1_fix
Configure the system to disable all wireless network interfaces.