Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Updating sysctl XCCDF naming #26

Merged
merged 2 commits into from
Aug 20, 2014
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions RHEL/6/input/auxiliary/stig_overlay.xml
Original file line number Diff line number Diff line change
Expand Up @@ -256,7 +256,7 @@
<VMSinfo VKey="38600" SVKey="50401" VRelease="1" />
<title>The system must not send ICMPv4 redirects by default.</title>
</overlay>
<overlay owner="disastig" ruleid="sysctl_ipv4_all_send_redirects" ownerid="RHEL-06-000081" disa="366" severity="medium">
<overlay owner="disastig" ruleid="sysctl_net_ipv4_conf_all_send_redirects" ownerid="RHEL-06-000081" disa="366" severity="medium">
<VMSinfo VKey="38601" SVKey="50402" VRelease="1" />
<title>The system must not send ICMPv4 redirects from any interface.</title>
</overlay>
Expand Down Expand Up @@ -316,7 +316,7 @@
<VMSinfo VKey="38546" SVKey="50347" VRelease="1" />
<title>The IPv6 protocol handler must not be bound to the network stack unless needed.</title>
</overlay>
<overlay owner="disastig" ruleid="sysctl_ipv6_default_accept_redirects" ownerid="RHEL-06-000099" disa="366" severity="medium">
<overlay owner="disastig" ruleid="sysctl_net_ipv6_conf_default_accept_redirects" ownerid="RHEL-06-000099" disa="366" severity="medium">
<VMSinfo VKey="38548" SVKey="50349" VRelease="2" />
<title>The system must ignore ICMPv6 redirects by default.</title>
</overlay>
Expand Down
2 changes: 1 addition & 1 deletion RHEL/6/input/auxiliary/transition_notes.xml
Original file line number Diff line number Diff line change
Expand Up @@ -1615,7 +1615,7 @@ sysctl_net_ipv4_conf_default_accept_redirects rule.
<note ref="22417" auth="KS">
Check does exist in the RHEL6 prose, it can be automated and OVAL for it does
exist.
rule=sysctl_ipv4_all_send_redirects manual=no
rule=sysctl_net_ipv4_conf_all_send_redirects manual=no
This check is split in the RHEL6 prose into the above and the
sysctl_net_ipv4_conf_default_send_redirects rule.
</note>
Expand Down
4 changes: 2 additions & 2 deletions RHEL/6/input/profiles/C2S.xml
Original file line number Diff line number Diff line change
Expand Up @@ -290,7 +290,7 @@ baseline.

<!-- CIS4.1.2 Disable Send Packet Redirects (Scored) -->
<select idref="sysctl_net_ipv4_conf_default_send_redirects" selected="true"/>
<select idref="sysctl_ipv4_all_send_redirects" selected="true"/>
<select idref="sysctl_net_ipv4_conf_all_send_redirects" selected="true"/>

<!-- CIS 4.2 Modify Network Parameters (Host and Router) -->
<!-- CIS 4.2.1 Disable Source Routed Packet Acceptance (Scored) -->
Expand Down Expand Up @@ -333,7 +333,7 @@ baseline.
<!-- NEEDS: net.ipv6.conf.all.accept_ra -->

<!-- CIS 4.4.1.2 Disable IPv6 Redirect Acceptance (Not Scored) -->
<select idref="sysctl_ipv6_default_accept_redirects" selected="true" />
<select idref="sysctl_net_ipv6_conf_default_accept_redirects" selected="true" />
<!-- NEEDS: net.ipv6.conf.default.accept_redirects -->

<!-- CIS 4.4.2 Disable IPv6 (Not Scored) -->
Expand Down
4 changes: 2 additions & 2 deletions RHEL/6/input/profiles/CS2.xml
Original file line number Diff line number Diff line change
Expand Up @@ -194,7 +194,7 @@

<select idref="network_disable_zeroconf" selected="true" />
<select idref="sysctl_net_ipv4_conf_default_send_redirects" selected="true"/>
<select idref="sysctl_ipv4_all_send_redirects" selected="true"/>
<select idref="sysctl_net_ipv4_conf_all_send_redirects" selected="true"/>
<select idref="sysctl_ipv4_ip_forward" selected="true"/>
<select idref="sysctl_net_ipv4_conf_all_accept_source_route" selected="true"/>
<select idref="sysctl_net_ipv4_conf_all_accept_redirects" selected="true"/>
Expand All @@ -217,7 +217,7 @@
<select idref="network_ipv6_default_gateway" selected="true" />
<select idref="network_ipv6_limit_requests" selected="true" />
<select idref="sysctl_net_ipv6_conf_default_accept_ra" selected="true" />
<select idref="sysctl_ipv6_default_accept_redirects" selected="true" />
<select idref="sysctl_net_ipv6_conf_default_accept_redirects" selected="true" />

<select idref="network_sniffer_disabled" selected="true" />
<select idref="wireless_disable_in_bios" selected="true" />
Expand Down
2 changes: 1 addition & 1 deletion RHEL/6/input/profiles/CSCF-RHEL6-MLS.xml
Original file line number Diff line number Diff line change
Expand Up @@ -92,7 +92,7 @@ for production deployment.</description>
<select idref="disable_rlogin" selected="true" />
<select idref="disable_rsh" selected="true" />
<select idref="sysctl_net_ipv4_conf_default_send_redirects" selected="true" />
<select idref="sysctl_ipv4_all_send_redirects" selected="true" />
<select idref="sysctl_net_ipv4_conf_all_send_redirects" selected="true" />
<select idref="sysctl_net_ipv4_conf_all_accept_source_route" selected="true" />
<select idref="sysctl_net_ipv4_conf_all_accept_redirects" selected="true" />
<select idref="sysctl_net_ipv4_conf_all_secure_redirects" selected="true" />
Expand Down
4 changes: 2 additions & 2 deletions RHEL/6/input/profiles/common.xml
Original file line number Diff line number Diff line change
Expand Up @@ -75,7 +75,7 @@
<select idref="sysctl_kernel_exec_shield" selected="true"/>

<select idref="sysctl_net_ipv4_conf_default_send_redirects" selected="true"/>
<select idref="sysctl_ipv4_all_send_redirects" selected="true"/>
<select idref="sysctl_net_ipv4_conf_all_send_redirects" selected="true"/>
<select idref="sysctl_ipv4_ip_forward" selected="true"/>
<select idref="sysctl_net_ipv4_conf_all_accept_source_route" selected="true"/>
<select idref="sysctl_net_ipv4_conf_all_accept_redirects" selected="true"/>
Expand All @@ -90,7 +90,7 @@
<select idref="sysctl_net_ipv4_conf_all_rp_filter" selected="true"/>
<select idref="sysctl_net_ipv4_conf_default_rp_filter" selected="true"/>
<select idref="kernel_module_ipv6_option_disabled" selected="true"/>
<select idref="sysctl_ipv6_default_accept_redirects" selected="true"/>
<select idref="sysctl_net_ipv6_conf_default_accept_redirects" selected="true"/>
<select idref="service_ip6tables_enabled" selected="true"/>
<select idref="service_iptables_enabled" selected="true"/>
<select idref="set_iptables_default_rule" selected="true"/>
Expand Down
4 changes: 2 additions & 2 deletions RHEL/6/input/profiles/fisma-medium-rhel6-server.xml
Original file line number Diff line number Diff line change
Expand Up @@ -252,7 +252,7 @@
<select idref="kernel_module_hfsplus_disabled" selected="true" />
<select idref="kernel_module_squashfs_disabled" selected="true" />
<select idref="kernel_module_udf_disabled" selected="true" />
<select idref="sysctl_ipv4_all_send_redirects" selected="true" />
<select idref="sysctl_net_ipv4_conf_all_send_redirects" selected="true" />
<select idref="sysctl_ipv4_ip_forward" selected="true" />
<select idref="sysctl_net_ipv4_conf_all_accept_source_route" selected="true" />
<select idref="sysctl_net_ipv4_icmp_echo_ignore_broadcasts" selected="true" />
Expand All @@ -269,7 +269,7 @@
<select idref="kernel_module_ipv6_option_disabled" selected="true" />
<select idref="network_ipv6_disable_rpc" selected="true" />
<select idref="sysctl_net_ipv6_conf_default_accept_ra" selected="true" />
<select idref="sysctl_ipv6_default_accept_redirects" selected="true" />
<select idref="sysctl_net_ipv6_conf_default_accept_redirects" selected="true" />

<!-- IA-2(1) -->
<select idref="bootloader_password" selected="true" />
Expand Down
4 changes: 2 additions & 2 deletions RHEL/6/input/profiles/nist-CL-IL-AL.xml
Original file line number Diff line number Diff line change
Expand Up @@ -301,7 +301,7 @@ assurance."</description>
<select idref="kernel_module_ipv6_option_disabled" selected="true" />
<select idref="network_ipv6_disable_rpc" selected="true" />
<select idref="sysctl_net_ipv6_conf_default_accept_ra" selected="true" />
<select idref="sysctl_ipv6_default_accept_redirects" selected="true" />
<select idref="sysctl_net_ipv6_conf_default_accept_redirects" selected="true" />
<select idref="network_disable_unused_interfaces" selected="true" />
<select idref="network_disable_zeroconf" selected="true" />
<select idref="network_sniffer_disabled" selected="true" />
Expand All @@ -311,7 +311,7 @@ assurance."</description>
<select idref="kernel_module_tipc_disabled" selected="true" />
<select idref="set_iptables_default_rule" selected="true" />
<select idref="set_iptables_default_rule_forward" selected="true" />
<select idref="sysctl_ipv4_all_send_redirects" selected="true" />
<select idref="sysctl_net_ipv4_conf_all_send_redirects" selected="true" />
<select idref="sysctl_ipv4_ip_forward" selected="true" />
<select idref="sysctl_net_ipv4_conf_all_accept_source_route" selected="true" />
<select idref="sysctl_net_ipv4_conf_all_accept_redirects" selected="true" />
Expand Down
4 changes: 2 additions & 2 deletions RHEL/6/input/profiles/usgcb-rhel6-server.xml
Original file line number Diff line number Diff line change
Expand Up @@ -116,7 +116,7 @@
<select idref="selinux_confinement_of_daemons" selected="true" />
<select idref="selinux_all_devicefiles_labeled" selected="true" />
<select idref="sysctl_ipv4_ip_forward" selected="true" />
<select idref="sysctl_ipv4_all_send_redirects" selected="true" />
<select idref="sysctl_net_ipv4_conf_all_send_redirects" selected="true" />
<select idref="sysctl_net_ipv4_conf_default_send_redirects" selected="true" />
<refine-value idref="sysctl_net_ipv4_conf_all_secure_redirects_value" selector="disabled" />
<select idref="sysctl_net_ipv4_conf_all_secure_redirects" selected="true" />
Expand Down Expand Up @@ -147,7 +147,7 @@
<select idref="network_ipv6_disable_rpc" selected="true" />
<refine-value idref="sysctl_net_ipv6_conf_default_accept_ra_value" selector="disabled" />
<select idref="sysctl_net_ipv6_conf_default_accept_ra" selected="true" />
<select idref="sysctl_ipv6_default_accept_redirects" selected="true" />
<select idref="sysctl_net_ipv6_conf_default_accept_redirects" selected="true" />
<select idref="service_ip6tables_enabled" selected="true" />
<select idref="service_iptables_enabled" selected="true" />
<select idref="set_iptables_default_rule" selected="true" />
Expand Down
2 changes: 1 addition & 1 deletion RHEL/6/input/system/network/ipv6.xml
Original file line number Diff line number Diff line change
Expand Up @@ -138,7 +138,7 @@ An illicit router advertisement message could result in a man-in-the-middle atta
<ref nist="CM-7" />
</Rule>

<Rule id="sysctl_ipv6_default_accept_redirects" severity="medium">
<Rule id="sysctl_net_ipv6_conf_default_accept_redirects" severity="medium">
<title>Disable Accepting IPv6 Redirects</title>
<description>
<sysctl-desc-macro sysctl="net.ipv6.conf.default.accept_redirects" value="0" />
Expand Down
2 changes: 1 addition & 1 deletion RHEL/6/input/system/network/kernel.xml
Original file line number Diff line number Diff line change
Expand Up @@ -28,7 +28,7 @@ only appropriate for systems acting as routers.</rationale>
<tested by="DS" on="20121024"/>
</Rule>

<Rule id="sysctl_ipv4_all_send_redirects" severity="medium">
<Rule id="sysctl_net_ipv4_conf_all_send_redirects" severity="medium">
<title>Disable Kernel Parameter for Sending ICMP Redirects for All Interfaces</title>
<description>
<sysctl-desc-macro sysctl="net.ipv4.conf.all.send_redirects" value="0" />
Expand Down