SRG-OS-000120-GPOS-00061 Controls

STIG IDVersionTitleProduct
AZLX-23-001105V1R3Amazon Linux 2023 must have the libreswan package installed.Amazon Linux 2023
AZLX-23-001120V1R3Amazon Linux 2023 must have the packages required for encrypting off-loaded audit logs installed.Amazon Linux 2023
ALMA-09-039510V1R6The libreswan package must be installed.AlmaLinux OS 9
ALMA-09-039620V1R6AlmaLinux OS 9 must have the packages required for encrypting offloaded audit logs installed.AlmaLinux OS 9
OL08-00-010159V2R8The OL 8 "pam_unix.so" module must be configured in the system-auth file to use a FIPS 140-2 approved cryptographic hashing algorithm for system authentication.Oracle Linux 8
OL08-00-010160V2R8The OL 8 "pam_unix.so" module must be configured in the password-auth file to use a FIPS 140-2 approved cryptographic hashing algorithm for system authentication.Oracle Linux 8
OL08-00-010161V2R8OL 8 must prevent system daemons from using Kerberos for authentication.Oracle Linux 8
OL08-00-010162V2R8The krb5-workstation package must not be installed on OL 8.Oracle Linux 8
OL08-00-010163V2R8The krb5-server package must not be installed on OL 8.Oracle Linux 8
OL09-00-000355V1R5OL 9 must have the packages required for encrypting offloaded audit logs installed.Oracle Linux 9
OL09-00-000410V1R5OL 9 must have the libreswan package installed.Oracle Linux 9
RHEL-10-200650V1R1RHEL 10 must have the packages required for encrypting off-loaded audit logs installed.Red Hat Enterprise Linux 10
RHEL-10-200680V1R1RHEL 10 must have the "libreswan" package installed.Red Hat Enterprise Linux 10
RHEL-08-010160V2R7The RHEL 8 pam_unix.so module must be configured in the password-auth file to use a FIPS 140-2 approved cryptographic hashing algorithm for system authentication.Red Hat Enterprise Linux 8
RHEL-08-010161V2R7RHEL 8 must prevent system daemons from using Kerberos for authentication.Red Hat Enterprise Linux 8
RHEL-08-010162V2R7The krb5-workstation package must not be installed on RHEL 8.Red Hat Enterprise Linux 8
RHEL-08-010163V2R7The krb5-server package must not be installed on RHEL 8.Red Hat Enterprise Linux 8
RHEL-08-010159V2R7The RHEL 8 pam_unix.so module must be configured in the system-auth file to use a FIPS 140-2 approved cryptographic hashing algorithm for system authentication.Red Hat Enterprise Linux 8
RHEL-09-672025V2R4RHEL 9 must use mechanisms meeting the requirements of applicable federal laws, executive orders, directives, policies, regulations, standards, and guidance for authentication to a cryptographic module.Red Hat Enterprise Linux 9
SLES-12-010210V3R4The SUSE operating system must employ FIPS 140-2 approved cryptographic hashing algorithm for system authentication (login.defs).SUSE Linux Enterprise 12
SLES-15-010260V2R7The SUSE operating system must employ FIPS 140-2 approved cryptographic hashing algorithm for system authentication (login.defs).SUSE Linux Enterprise 15
TOSS-04-010060V2R5The TOSS pam_unix.so module must be configured in the password-auth file to use a FIPS 140-2-approved cryptographic hashing algorithm for system authentication.Tri-Lab Operating System Stack
TOSS-04-010070V2R5The TOSS pam_unix.so module must be configured in the system-auth file to use a FIPS 140-2-approved cryptographic hashing algorithm for system authentication.Tri-Lab Operating System Stack
UBTU-18-010110V2R15The Ubuntu operating system must employ a FIPS 140-2 approved cryptographic hashing algorithms for all created and stored passwords.Ubuntu 18.04
UBTU-20-010404V2R3The Ubuntu operating system must encrypt all stored passwords with a FIPS 140-2 approved cryptographic hashing algorithm.Ubuntu 20.04
UBTU-22-611070V2R8Ubuntu 22.04 LTS must encrypt all stored passwords with a FIPS 140-3-approved cryptographic hashing algorithm.Ubuntu 22.04
UBTU-24-400400V1R5Ubuntu 24.04 LTS must encrypt all stored passwords with a FIPS 140-3 approved cryptographic hashing algorithm.Ubuntu 24.04
WN10-CC-000052V3R6Windows 10 must be configured to prioritize ECC Curves with longer key lengths first.Microsoft Windows 10
WN10-SO-000190V3R6Kerberos encryption types must be configured to prevent the use of DES and RC4 encryption suites.Microsoft Windows 10
WN11-CC-000052V2R7Windows 11 must be configured to prioritize ECC Curves with longer key lengths first.Microsoft Windows 11
WN11-SO-000190V2R7Kerberos encryption types must be configured to prevent the use of DES and RC4 encryption suites.Microsoft Windows 11
WN16-SO-000350V2R9Kerberos encryption types must be configured to prevent the use of DES and RC4 encryption suites.Microsoft Windows Server 2016
WN19-SO-000290V3R8Windows Server 2019 Kerberos encryption types must be configured to prevent the use of DES and RC4 encryption suites.Microsoft Windows Server 2019
WN22-SO-000290V2R8Windows Server 2022 Kerberos encryption types must be configured to prevent the use of DES and RC4 encryption suites.Microsoft Windows Server 2022
WN25-SO-000290V1R1Windows Server 2025 Kerberos encryption types must be configured to prevent the use of DES and RC4 encryption suites.Microsoft Windows Server 2025