UCF STIG Viewer Logo

SUSE Linux Enterprise Server 15 Security Technical Implementation Guide


Overview

Date Finding Count (232)
2021-03-04 CAT I (High): 18 CAT II (Med): 192 CAT III (Low): 22
STIG Description
This Security Technical Implementation Guide is published as a tool to improve the security of Department of Defense (DoD) information systems. The requirements are derived from the National Institute of Standards and Technology (NIST) 800-53 and related documents. Comments or proposed revisions to this document should be sent via email to the following address: disa.stig_spt@mail.mil.

Available Profiles



Findings (MAC I - Mission Critical Classified)

Finding ID Severity Title
V-234820 High SUSE operating systems with Unified Extensible Firmware Interface (UEFI) implemented must require authentication upon booting into single-user mode and maintenance.
V-234985 High There must be no shosts.equiv files on the SUSE operating system.
V-234984 High There must be no .shosts files on the SUSE operating system.
V-234988 High The SUSE operating system must disable the x86 Ctrl-Alt-Delete key sequence.
V-234898 High The SUSE operating system must not be configured to allow blank or null passwords.
V-234800 High The SUSE operating system must be a vendor-supported release.
V-234804 High The SUSE operating system must not have the vsftpd package installed if not required for operational support.
V-234860 High All networked SUSE operating systems must have and implement SSH to protect the confidentiality and integrity of transmitted and received information, as well as information during preparation for transmission.
V-234989 High The SUSE operating system must disable the x86 Ctrl-Alt-Delete key sequence for Graphical User Interfaces.
V-234819 High SUSE operating systems with a basic input/output system (BIOS) must require authentication upon booting into single-user and maintenance modes.
V-234818 High The SUSE operating system must not have the telnet-server package installed.
V-234876 High The SUSE operating system root account must be the only account with unrestricted access to the system.
V-234853 High The SUSE operating system must reauthenticate users when changing authenticators, roles, or escalating privileges.
V-234852 High The SUSE operating system tool zypper must have gpgcheck enabled.
V-234990 High The SUSE operating system must disable the systemd Ctrl-Alt-Delete burst key sequence.
V-234859 High FIPS 140-2 mode must be enabled on the SUSE operating system.
V-235031 High The SUSE operating system must not allow unattended or automatic logon via the graphical user interface (GUI).
V-235032 High The SUSE operating system must not allow unattended or automatic logon via SSH.
V-234824 Medium The SUSE operating system must employ FIPS 140-2 approved cryptographic hashing algorithm for system authentication (system-auth).
V-234825 Medium The SUSE operating system must employ FIPS 140-2 approved cryptographic hashing algorithm for system authentication (login.defs).
V-234826 Medium The SUSE operating system SSH daemon must be configured to only use Message Authentication Codes (MACs) employing FIPS 140-2 approved cryptographic hash algorithms.
V-234827 Medium The SUSE operating system SSH daemon must be configured with a timeout interval.
V-234821 Medium The SUSE operating system must be configured to prohibit or restrict the use of functions, ports, protocols, and/or services as defined in the Ports, Protocols, and Services Management (PPSM) Category Assignments List (CAL) and vulnerability assessments.
V-234822 Medium The SUSE operating system must not have duplicate User IDs (UIDs) for interactive users.
V-234823 Medium The SUSE operating system must disable the file system automounter unless required.
V-234983 Medium The SUSE operating system must enforce a delay of at least four seconds between logon prompts following a failed logon attempt.
V-234982 Medium The SUSE operating system must enforce a delay of at least four seconds between logon prompts following a failed logon attempt.
V-234981 Medium The SUSE operating system must not disable syscall auditing.
V-234828 Medium The sticky bit must be set on all SUSE operating system world-writable directories.
V-234829 Medium The SUSE operating system must be configured to use TCP syncookies.
V-235027 Medium The SUSE operating system must not have network interfaces in promiscuous mode unless approved and documented.
V-235026 Medium The SUSE operating system must not be performing Internet Protocol version 6 (IPv6) packet forwarding by default unless the system is a router.
V-235025 Medium The SUSE operating system must not be performing Internet Protocol version 6 (IPv6) packet forwarding unless the system is a router.
V-235024 Medium The SUSE operating system must not be performing Internet Protocol version 4 (IPv4) packet forwarding unless the system is a router.
V-235023 Medium The SUSE operating system must not send Internet Protocol version 4 (IPv4) Internet Control Message Protocol (ICMP) redirects.
V-235022 Medium The SUSE operating system must not allow interfaces to send Internet Protocol version 4 (IPv4) Internet Control Message Protocol (ICMP) redirect messages by default.
V-235021 Medium The SUSE operating system must not allow interfaces to accept Internet Protocol version 6 (IPv6) Internet Control Message Protocol (ICMP) redirect messages by default.
V-235020 Medium The SUSE operating system must prevent Internet Protocol version 6 (IPv6) Internet Control Message Protocol (ICMP) redirect messages from being accepted.
V-235029 Medium All SUSE operating system files and directories must have a valid group owner.
V-235028 Medium All SUSE operating system files and directories must have a valid owner.
V-234910 Medium The SUSE operating system must generate audit records for all uses of the unix_chkpwd or unix2_chkpwd commands.
V-234911 Medium The SUSE operating system must generate audit records for all uses of the chage command.
V-234912 Medium The SUSE operating system must generate audit records for all uses of the crontab command.
V-234913 Medium The SUSE operating system must audit all uses of the sudoers file and all files in the /etc/sudoers.d/ directory.
V-234914 Medium The SUSE operating system must generate audit records for all uses of the open system call.
V-234915 Medium The SUSE operating system must generate audit records for all uses of the creat system call.
V-234916 Medium The SUSE operating system must generate audit records for all uses of the openat system call.
V-234917 Medium The SUSE operating system must generate audit records for all uses of the open_by_handle_at system call.
V-234918 Medium The SUSE operating system must generate audit records for all uses of the removexattr system call.
V-234919 Medium The SUSE operating system must generate audit records for all uses of the lremovexattr system call.
V-234837 Medium The SUSE operating system library directories must be owned by root.
V-234836 Medium The SUSE operating system library files must be owned by root.
V-234835 Medium The SUSE operating system library directories must have mode 0755 or less permissive.
V-234834 Medium The SUSE operating system library files must have mode 0755 or less permissive.
V-234833 Medium The SUSE operating system must prevent unauthorized users from accessing system error messages.
V-234832 Medium The SUSE operating system must generate error messages that provide information necessary for corrective actions without revealing information that could be exploited by adversaries.
V-234831 Medium All SUSE operating system persistent disk partitions must implement cryptographic mechanisms to prevent unauthorized disclosure or modification of all information that requires at-rest protection.
V-234830 Medium The SUSE operating system for all network connections associated with SSH traffic must immediately terminate at the end of the session or after 10 minutes of inactivity.
V-234839 Medium The SUSE operating system library directories must be group-owned by root.
V-234838 Medium The SUSE operating system library files must be group-owned by root.
V-235018 Medium The SUSE operating system must prevent Internet Protocol version 4 (IPv4) Internet Control Message Protocol (ICMP) redirect messages from being accepted.
V-235019 Medium The SUSE operating system must not allow interfaces to accept Internet Protocol version 4 (IPv4) Internet Control Message Protocol (ICMP) redirect messages by default.
V-235012 Medium The SUSE operating system SSH daemon must not allow compression or must only allow compression after successful authentication.
V-235013 Medium The SUSE operating system SSH daemon must disable forwarded remote X connections for interactive users, unless to fulfill documented and validated mission requirements.
V-235010 Medium The SUSE operating system SSH daemon must perform strict mode checking of home directory configuration files.
V-235016 Medium The SUSE operating system must not forward Internet Protocol version 4 (IPv4) source-routed packets by default.
V-235017 Medium The SUSE operating system must not forward Internet Protocol version 6 (IPv6) source-routed packets by default.
V-235014 Medium The SUSE operating system must not forward Internet Protocol version 4 (IPv4) source-routed packets.
V-235015 Medium The SUSE operating system must not forward Internet Protocol version 6 (IPv6) source-routed packets.
V-234899 Medium The SUSE operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd.
V-234903 Medium The SUSE operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/gshadow.
V-234902 Medium The SUSE operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/security/opasswd.
V-234901 Medium The SUSE operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/shadow.
V-234900 Medium The SUSE operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/group.
V-234906 Medium The SUSE operating system must generate audit records for all uses of the passwd command.
V-234904 Medium SUSE operating system audit records must contain information to establish what type of events occurred, the source of events, where events occurred, and the outcome of events.
V-234851 Medium Advanced Intrusion Detection Environment (AIDE) must verify the baseline SUSE operating system configuration at least weekly.
V-235009 Medium The SUSE operating system SSH daemon private host key files must have mode 0600 or less permissive.
V-235008 Medium The SUSE operating system SSH daemon public host key files must have mode 0644 or less permissive.
V-235007 Medium The SUSE operating system SSH daemon must be configured to not allow authentication using known hosts authentication.
V-235006 Medium The SUSE operating system must be configured to not overwrite Pluggable Authentication Modules (PAM) configuration on package changes.
V-235001 Medium SUSE operating system file systems that are being imported via Network File System (NFS) must be mounted to prevent binary files from being executed.
V-235000 Medium SUSE operating system file systems that are being imported via Network File System (NFS) must be mounted to prevent files with the setuid and setgid bit set from being executed.
V-235003 Medium SUSE operating system kernel core dumps must be disabled unless needed.
V-235002 Medium All SUSE operating system world-writable directories must be group-owned by root, sys, bin, or an application group.
V-234937 Medium The SUSE operating system must generate audit records for all uses of the insmod command.
V-234932 Medium The SUSE operating system must generate audit records for all uses of the sudoedit command.
V-234930 Medium The SUSE operating system must generate audit records for all uses of the fchmodat system call.
V-234931 Medium The SUSE operating system must generate audit records for all uses of the ftruncate system call.
V-234938 Medium The SUSE operating system must generate audit records for all uses of the rmmod command.
V-234939 Medium The SUSE operating system must generate audit records for all uses of the modprobe command.
V-234891 Medium The SUSE operating system must be configured to create or update passwords with a maximum lifetime of 60 days.
V-234890 Medium The SUSE operating system must employ user passwords with a minimum lifetime of 24 hours (one day).
V-234882 Medium The SUSE operating system must enforce passwords that contain at least one uppercase character.
V-234883 Medium The SUSE operating system must enforce passwords that contain at least one lowercase character.
V-234880 Medium All SUSE operating system local interactive user accounts, upon creation, must be assigned a home directory.
V-234881 Medium The SUSE operating system must display the date and time of the last successful account logon upon an SSH logon.
V-234886 Medium The SUSE operating system must configure the Linux Pluggable Authentication Modules (PAM) to only store encrypted representations of passwords.
V-234887 Medium The SUSE operating system must employ FIPS 140-2-approved cryptographic hashing algorithms for all stored passwords.
V-234884 Medium The SUSE operating system must enforce passwords that contain at least one numeric character.
V-234885 Medium The SUSE operating system must require the change of at least eight of the total number of characters when passwords are changed.
V-234921 Medium The SUSE operating system must generate audit records for all uses of the setxattr system call.
V-234920 Medium The SUSE operating system must generate audit records for all uses of the fremovexattr system call.
V-234888 Medium The SUSE operating system must employ FIPS 140-2-approved cryptographic hashing algorithms for all stored passwords.
V-234889 Medium The SUSE operating system must be configured to create or update passwords with a minimum lifetime of 24 hours (one day).
V-234925 Medium The SUSE operating system must generate audit records for all uses of the fchown system call.
V-234924 Medium The SUSE operating system must generate audit records for all uses of the chown system call.
V-234927 Medium The SUSE operating system must generate audit records for all uses of the fchownat system call.
V-234926 Medium The SUSE operating system must generate audit records for all uses of the lchown system call.
V-234808 Medium The SUSE operating system must display a banner before granting local or remote access to the system via a graphical user logon.
V-234809 Medium The SUSE operating system must display the approved Standard Mandatory DoD Notice before granting local or remote access to the system via a graphical user logon.
V-234802 Medium Vendor-packaged SUSE operating system security patches and updates must be installed and up to date.
V-234803 Medium The SUSE operating system must display the Standard Mandatory DoD Notice and Consent Banner before granting access via local console.
V-234801 Medium The SUSE operating system must deploy Endpoint Security for Linux Threat Prevention (ENSLTP).
V-234806 Medium The SUSE operating system must display the Standard Mandatory DoD Notice and Consent Banner until users acknowledge the usage conditions and take explicit actions to log on for further access to the local graphical user interface (GUI).
V-234807 Medium The SUSE operating system file /etc/gdm/banner must contain the Standard Mandatory DoD Notice and Consent banner text.
V-234805 Medium The SUSE operating system must display the Standard Mandatory DoD Notice and Consent Banner before granting access via SSH.
V-234869 Medium The SUSE operating system must implement multifactor authentication for access to privileged accounts via pluggable authentication modules (PAM).
V-234861 Medium The SUSE operating system must implement kptr-restrict to prevent the leaking of internal kernel addresses.
V-234862 Medium Address space layout randomization (ASLR) must be implemented by the SUSE operating system to protect memory from unauthorized code execution.
V-234863 Medium The SUSE operating system must remove all outdated software components after updated versions have been installed.
V-234864 Medium The SUSE operating system must notify the System Administrator (SA) when Advanced Intrusion Detection Environment (AIDE) discovers anomalies in the operation of any security functions.
V-234865 Medium The SUSE operating system must off-load rsyslog messages for networked systems in real time and off-load standalone systems at least weekly.
V-234866 Medium The SUSE operating system must provision temporary accounts with an expiration date for 72 hours.
V-234867 Medium The SUSE operating system must lock an account after three consecutive invalid access attempts.
V-234895 Medium The SUSE operating system must employ passwords with a minimum of 15 characters.
V-234894 Medium The SUSE operating system must not allow passwords to be reused for a minimum of five generations.
V-234897 Medium The SUSE operating system must prevent the use of dictionary words for passwords.
V-234896 Medium The SUSE operating system must enforce passwords that contain at least one special character.
V-234958 Medium The SUSE operating system audit system must take appropriate action when the audit storage volume is full.
V-234959 Medium The SUSE operating system must protect audit rules from unauthorized modification.
V-234893 Medium The SUSE operating system must employ a password history file.
V-234892 Medium The SUSE operating system must employ user passwords with a maximum lifetime of 60 days.
V-234954 Medium The SUSE operating system must generate audit records for all uses of the su command.
V-234956 Medium The Information System Security Officer (ISSO) and System Administrator (SA), at a minimum, must be alerted of a SUSE operating system audit processing failure event.
V-234957 Medium The Information System Security Officer (ISSO) and System Administrator (SA), at a minimum, must have mail aliases to be notified of a SUSE operating system audit processing failure.
V-234950 Medium The SUSE operating system must generate audit records for all uses of the pam_timestamp_check command.
V-234951 Medium The SUSE operating system must generate audit records for all uses of the delete_module system call.
V-234952 Medium The SUSE operating system must generate audit records for all uses of the finit_module system call.
V-234953 Medium The SUSE operating system must generate audit records for all uses of the init_module system call.
V-234815 Medium The SUSE operating system must log SSH connection attempts and failures to the server.
V-234817 Medium The SUSE operating system, for PKI-based authentication, must validate certificates by constructing a certification path (which includes status information) to an accepted trust anchor.
V-234816 Medium The SUSE operating system must implement DoD-approved encryption to protect the confidentiality of SSH remote connections.
V-234810 Medium The SUSE operating system must be able to lock the graphical user interface (GUI).
V-234813 Medium The SUSE operating system must initiate a session lock after a 15-minute period of inactivity.
V-234812 Medium The SUSE operating system must initiate a session lock after a 15-minute period of inactivity for the graphical user interface (GUI).
V-234929 Medium The SUSE operating system must generate audit records for all uses of the fchmod system call.
V-234879 Medium The SUSE operating system must use the invoking user's password for privilege escalation when using "sudo".
V-234878 Medium The SUSE operating system must require re-authentication when using the "sudo" command.
V-234928 Medium The SUSE operating system must generate audit records for all uses of the chmod system call.
V-234872 Medium The SUSE operating system must never automatically remove or disable emergency administrator accounts.
V-234871 Medium The SUSE operating system must disable account identifiers (individuals, groups, roles, and devices) after 35 days of inactivity after password expiration.
V-234870 Medium The SUSE operating system must deny direct logons to the root account using remote access via SSH.
V-234877 Medium The SUSE operating system must restrict privilege elevation to authorized personnel.
V-234875 Medium The SUSE operating system must not have unnecessary account capabilities.
V-234874 Medium The SUSE operating system must not have unnecessary accounts.
V-234961 Medium The SUSE operating system audit tools must have the proper permissions configured to protect against unauthorized access.
V-234960 Medium The SUSE operating system must generate audit records for all uses of the truncate command.
V-234949 Medium The SUSE operating system must generate audit records for all uses of the usermod command.
V-234948 Medium The SUSE operating system must generate audit records for all uses of the passmass command.
V-234947 Medium The SUSE operating system must generate audit records for all modifications to the lastlog file.
V-234946 Medium The SUSE operating system must generate audit records for all modifications to the tallylog file must generate an audit record.
V-234945 Medium The SUSE operating system must generate audit records for all uses of the rm command.
V-234944 Medium The SUSE operating system must generate audit records for all uses of the chcon command.
V-234943 Medium The SUSE operating system must generate audit records for all uses of the chacl command.
V-234942 Medium The SUSE operating system must generate audit records for all uses of the setfacl command.
V-234941 Medium The SUSE operating system must generate audit records for all uses of the chmod command.
V-234940 Medium The SUSE operating system must generate audit records for all uses of the kmod command.
V-234923 Medium The SUSE operating system must generate audit records for all uses of the lsetxattr system call.
V-234922 Medium The SUSE operating system must generate audit records for all uses of the fsetxattr system call.
V-234848 Medium SUSE operating system AppArmor tool must be configured to control whitelisted applications and user home directory access control.
V-234849 Medium The SUSE operating system clock must, for networked systems, be synchronized to an authoritative DoD time source at least every 24 hours.
V-234846 Medium The SUSE operating system must have a firewall system installed to immediately disconnect or disable remote access to the whole operating system.
V-234847 Medium The SUSE operating system wireless network adapters must be disabled unless approved and documented.
V-234844 Medium The SUSE operating system must have system commands group-owned by root.
V-234845 Medium The SUSE operating system must have directories that contain system commands group-owned by root.
V-234842 Medium The SUSE operating system must have system commands owned by root.
V-234843 Medium The SUSE operating system must have directories that contain system commands owned by root.
V-234840 Medium The SUSE operating system must have system commands set to a mode of 0755 or less permissive.
V-234841 Medium The SUSE operating system must have directories that contain system commands set to a mode of 0755 or less permissive.
V-234972 Medium The SUSE operating system must generate audit records for all uses of the renameat2 system call.
V-234973 Medium The SUSE operating system must generate audit records for all uses of the unlink system call.
V-234970 Medium The SUSE operating system must generate audit records for all uses of the rename system call.
V-234971 Medium The SUSE operating system must generate audit records for all uses of the renameat system call.
V-234976 Medium The SUSE operating system must generate audit records for the /var/log/wtmp file.
V-234977 Medium The SUSE operating system must generate audit records for the /var/log/btmp file.
V-234974 Medium The SUSE operating system must generate audit records for all uses of the unlinkat system call.
V-234975 Medium The SUSE operating system must generate audit records for the /run/utmp file.
V-234978 Medium The SUSE operating system must off-load audit records onto a different system or media from the system being audited.
V-234979 Medium Audispd must take appropriate action when the SUSE operating system audit storage is full.
V-234998 Medium SUSE operating system file systems that contain user home directories must be mounted to prevent files with the setuid and setgid bit set from being executed.
V-234999 Medium SUSE operating system file systems that are used with removable media must be mounted to prevent files with the setuid and setgid bit set from being executed.
V-234855 Medium The SUSE operating system must implement certificate status checking for multifactor authentication.
V-234854 Medium The SUSE operating system must have the packages required for multifactor authentication to be installed.
V-234857 Medium If Network Security Services (NSS) is being used by the SUSE operating system it must prohibit the use of cached authentications after one day.
V-234856 Medium The SUSE operating system must disable the USB mass storage kernel module.
V-234858 Medium The SUSE operating system must configure the Linux Pluggable Authentication Modules (PAM) to prohibit the use of cached offline authentications after one day.
V-234992 Medium All SUSE operating system local interactive user home directories defined in the /etc/passwd file must exist.
V-234993 Medium All SUSE operating system local interactive user home directories must have mode 0750 or less permissive.
V-234994 Medium All SUSE operating system local interactive user home directories must be group-owned by the home directory owner's primary group.
V-234995 Medium All SUSE operating system local initialization files must have mode 0740 or less permissive.
V-234996 Medium All SUSE operating system local interactive user initialization files executable search paths must contain only paths that resolve to the users home directory.
V-234997 Medium All SUSE operating system local initialization files must not execute world-writable programs.
V-234991 Medium All SUSE operating system local interactive users must have a home directory assigned in the /etc/passwd file.
V-234965 Medium The SUSE operating system must allocate audit record storage capacity to store at least one week of audit records when audit records are not immediately sent to a central audit record storage facility.
V-234964 Medium The SUSE operating system must have the auditing package installed.
V-234966 Medium The audit-audispd-plugins must be installed on the SUSE operating system.
V-235030 Medium The SUSE operating system default permissions must be defined in such a way that all authenticated users can only read and modify their own files.
V-234962 Medium The SUSE operating system file integrity tool must be configured to protect the integrity of the audit tools.
V-234969 Medium The SUSE operating system auditd service must notify the System Administrator (SA) and Information System Security Officer (ISSO) immediately when audit storage capacity is 75 percent full.
V-234980 Low The SUSE operating system must use a separate file system for the system audit data path.
V-234987 Low The SUSE operating system file integrity tool must be configured to verify extended attributes.
V-234907 Low The SUSE operating system must generate audit records for all uses of the gpasswd command.
V-234905 Low The SUSE operating system must generate audit records for all uses of the ssh-keysign command.
V-234909 Low The SUSE operating system must generate audit records for a uses of the chsh command.
V-234908 Low The SUSE operating system must generate audit records for all uses of the newgrp command.
V-234986 Low The SUSE operating system file integrity tool must be configured to verify Access Control Lists (ACLs).
V-234850 Low The SUSE operating system must be configured to use Coordinated Universal Time (UTC) or Greenwich Mean Time (GMT).
V-235005 Low The SUSE operating system must use a separate file system for /var.
V-235004 Low A separate file system must be used for SUSE operating system user home directories (such as /home or an equivalent).
V-234936 Low The SUSE operating system must generate audit records for all uses of the ssh-agent command.
V-234934 Low The SUSE operating system must generate audit records for all uses of the mount system call.
V-234935 Low The SUSE operating system must generate audit records for all uses of the umount system call.
V-234933 Low The SUSE operating system must generate audit records for all uses of the chfn command.
V-234868 Low The SUSE operating system must limit the number of concurrent sessions to 10 for all accounts and/or account types.
V-234955 Low The SUSE operating system must generate audit records for all uses of the sudo command.
V-234814 Low The SUSE operating system must conceal, via the session lock, information previously visible on the display with a publicly viewable image in the graphical user interface (GUI).
V-234811 Low The SUSE operating system must utilize vlock to allow for session locking.
V-234873 Low The SUSE operating system must display the date and time of the last successful account logon upon logon.
V-234963 Low The SUSE operating system must generate audit records for all uses of the privileged functions.
V-234967 Low The SUSE operating system audit event multiplexor must be configured to use Kerberos.
V-234968 Low Audispd must off-load audit records onto a different system or media from the SUSE operating system being audited.