☐ Open an SSH session back into the RHEL 9 server and install opensecap-scanner and scap-security-guide with the following commands.
Updating Subscription Management repositories.
Last metadata expiration check: 1:21:46 ago on Sat 23 May 2026 01:02:10 PM EDT.
Package openscap-scanner-1:1.3.13-1.el9_7.x86_64 is already installed.
Package scap-security-guide-0.1.80-1.el9_7.noarch is already installed.
Dependencies resolved.
Nothing to do.
Complete!
Document type: Source Data Stream
Imported: 2026-03-18T05:35:29
Stream: scap_org.open-scap_datastream_from_xccdf_ssg-rhel9-xccdf.xml
Generated: 2026-03-11T00:00:00
Version: 1.3
Profile
Title: DISA STIG for Red Hat Enterprise Linux 9
Id: xccdf_org.ssgproject.content_profile_stig
Description: This profile contains configuration checks that align to the DISA STIG for Red Hat Enterprise Linux 9 V2R7. In addition to being applicable to Red Hat Enterprise Linux 9, this configuration baseline is applicable to the operating system tier of Red Hat technologies that are based on Red Hat Enterprise Linux 9, such as: - Red Hat Enterprise Linux Server - Red Hat Enterprise Linux Workstation and Desktop - Red Hat Enterprise Linux for HPC - Red Hat Storage - Red Hat Containers with a Red Hat Enterprise Linux 9 image
☐ Scan the system and generate the eXtensible Configuration Checklist Description Format (XCCDF) HTML report using the following commands.
(Replace admin with the account name you created at the beginning of Part 1)
Rule xccdf_org.ssgproject.content_rule_auditd_write_logs
Ident CCE-83705-4
Result pass
Title Verify Permissions on /etc/audit/auditd.conf
Rule xccdf_org.ssgproject.content_rule_file_permissions_etc_audit_auditd
Ident CCE-89284-4
Result pass
total 5148
-rw-------. 1 root root 5270296 May 23 15:13 rhel98.html
[root@RHEL98 ~]# chown john:john /home/john/rhel98.html
total 5148
-rw-------. 1 john john 5270296 May 23 15:13 rhel98.html
[root@RHEL98 ~]#
You are accessing a U.S. Government (USG) Information System (IS) that is
provided for USG-authorized use only. By using this IS (which includes any
device attached to this IS), you consent to the following conditions:
-The USG routinely intercepts and monitors communications on this IS for
purposes including, but not limited to, penetration testing, COMSEC monitoring,
communications and work product are private and confidential. See User
Agreement for details.
john@192.168.122.117's password: ************
rhel98.html 100% 5147KB 273.0MB/s 00:00
CONCLUSION
☐ Application of the DISA STIG via automated means is not a 100% solution, nor is STIG application a "one and done" process. New STIGs are released periodically and systems need to be re-checked and re-evaluated against them when they are.
☐ The OpenSCAP Evaluation Report is an interactive web page with sections that expand and collapse. There are explanations and instructions on how to remediate the medium (Cat 2) and high (Cat 1) findings within the report.
No comments:
Post a Comment