SRG-OS-000396-GPOS-00176 Controls

STIG IDVersionTitleProduct
OL09-00-000240V1R3OL 9 must have the crypto-policies package installed.
OL09-00-000241V1R3OL 9 must implement a FIPS 140-3 compliant system-wide cryptographic policy.
OL09-00-000242V1R3OL 9 must not allow the cryptographic policy to be overridden.
RHEL-09-215100V2R6RHEL 9 must have the crypto-policies package installed.
RHEL-09-672020V2R6RHEL 9 cryptographic policy must not be overridden.
RHEL-09-215105V2R6RHEL 9 must implement a FIPS 140-3-compliant systemwide cryptographic policy.
SLES-15-010510V2R4FIPS 140-2 mode must be enabled on the SUSE operating system.
UBTU-20-010442V2R3The Ubuntu operating system must implement NIST FIPS-validated cryptography to protect classified information and for the following: To provision digital signatures, to generate cryptographic hashes, and to protect unclassified information requiring confidentiality and cryptographic protection in accordance with applicable federal laws, Executive Orders, directives, policies, regulations, and standards.
UBTU-22-671010V2R6Ubuntu 22.04 LTS must implement NIST FIPS-validated cryptography to protect classified information and for the following: To provision digital signatures, to generate cryptographic hashes, and to protect unclassified information requiring confidentiality and cryptographic protection in accordance with applicable federal laws, Executive Orders, directives, policies, regulations, and standards.
UBTU-22-432011V2R6The operating system must require users to provide a password for privilege escalation.
UBTU-22-654224V2R6The operating system must restrict privilege elevation to authorized personnel.
UBTU-22-654041V2R6Ubuntu 22.04 LTS must audit any script or executable called by cron as root or by any privileged user.
UBTU-22-254025V2R6Ubuntu 22.04 LTS must be configured such that Pluggable Authentication Module (PAM) prohibits the use of cached authentications after one day.
UBTU-22-254010V2R6Ubuntu 22.04 LTS must have the "SSSD" package installed.
UBTU-22-254030V2R6Ubuntu 22.04 LTS must map the authenticated identity to the user or group account for PKI-based authentication.
UBTU-22-254015V2R6Ubuntu 22.04 LTS must use the "SSSD" package for multifactor authentication services.
UBTU-22-254020V2R6Ubuntu 22.04 LTS must ensure SSSD performs certificate path validation, including revocation checking, against a trusted anchor for PKI-based authentication.
WN16-DC-000140V2R9Separate, NSA-approved (Type 1) cryptography must be used to protect the directory data in transit for directory service implementations at a classified confidentiality level when replication data traverses a network cleared to a lower level than the data.
WN19-DC-000140V3R6Windows Server 2019 must use separate, NSA-approved (Type 1) cryptography to protect the directory data in transit for directory service implementations at a classified confidentiality level when replication data traverses a network cleared to a lower level than the data.
WN22-DC-000140V2R6Windows Server 2022 must use separate, NSA-approved (Type 1) cryptography to protect the directory data in transit for directory service implementations at a classified confidentiality level when replication data traverses a network cleared to a lower level than the data.